CVE-2022-28448
PoC —CVSS 3.1
5.4 medium
EPSS
<1%p41
Published
()
Modified
Description
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info.
- Vendors
- nopcommerce
- Products
- nopcommerce
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.