ZeroHour

CVE-2022-28448

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p41
Published
()
Modified
Description

nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info.

Vendors
nopcommerce
Products
nopcommerce
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.