What the vulnerability does
01Description
Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions.
Explanation of Vulnerability in Simple Terms
AfterShip Tracking versions up to 1.18.1 contain a cross-site scripting (XSS) vulnerability that allows an attacker to inject malicious scripts. A logged-in user must visit a crafted page or link for the attack to execute. The vulnerability can affect other users and compromise site integrity, though the impact is limited to low-severity data exposure.
What an attacker can do
Inject malicious scripts that execute in other users' browsers when they visit a crafted page.
Potential impact on your site
Logged-in users could have their sessions compromised or data stolen if they visit attacker-controlled pages.
Conditions required to exploit
Attacker needs a low-privilege account and the victim must click a malicious link or visit a crafted page.
Key dates
External resources
Related vulnerabilities