MEDIUM
app1pro Shopicial search cross site scripting
Published Sep 15, 2023
6.1
MEDIUMCVSS 3.1
EPSS 0.49%
Description
A vulnerability was found in app1pro Shopicial up to 20230830. It has been declared as problematic. This vulnerability affects unknown code of the file search. The manipulation of the argument from with the input comments</script>'"><img src=x onerror=alert(document.cookie)> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-239794 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 20230830StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-54813 Advisory
- https://vuldb.com/?ctiid.239794 signatureThird Party Advisory
- https://vuldb.com/?id.239794 vdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-54813 | Advisory | |
| https://vuldb.com/?ctiid.239794 | signatureThird Party Advisory | |
| https://vuldb.com/?id.239794 | vdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Sep 15, 2023
Updated Aug 2, 2024
Reserved Sep 15, 2023
Link CVE-2023-4983
CISA Vulnrichment
Updated Jul 11, 2024
ENISA EUVD
EUVD-2023-54813 Assigner VulDB
Published Sep 15, 2023
Updated Aug 2, 2024
Exploited since n/a
Link EUVD-2023-54813