ZeroHour

CVE-2022-28449

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p52
Published
()
Modified
Description

nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upload an arbitrary file to the system.

Vendors
nopcommerce
Products
nopcommerce
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.