ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing POST parameters.
History

Wed, 04 Sep 2024 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Shopxo
Shopxo shopxo
Weaknesses CWE-79
CPEs cpe:2.3:a:shopxo:shopxo:6.2.0:*:*:*:*:*:*:*
Vendors & Products Shopxo
Shopxo shopxo
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Tue, 03 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 30 Aug 2024 22:00:00 +0000

Type Values Removed Values Added
Description ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing POST parameters.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-08-30T00:00:00

Updated: 2024-09-03T14:55:01.267Z

Reserved: 2024-08-21T00:00:00

Link: CVE-2024-44682

cve-icon Vulnrichment

Updated: 2024-09-03T14:54:52.703Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-30T22:15:06.703

Modified: 2024-09-04T16:38:36.817

Link: CVE-2024-44682

cve-icon Redhat

No data.