VYPR
Moderate severityOSV Advisory· Published May 1, 2022· Updated Sep 16, 2024

Cross-site Scripting (XSS)

CVE-2022-21149

Description

The package s-cart/s-cart before 6.9; the package s-cart/core before 6.9 are vulnerable to Cross-site Scripting (XSS) which can lead to cookie stealing of any victim that visits the affected URL so the attacker can gain unauthorized access to that user's account through the stolen cookie.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
s-cart/corePackagist
< 6.96.9
s-cart/s-cartPackagist
< 6.96.9

Affected products

1
  • Range: 4.0.0, 4.0.0-beta, 4.0.1, …

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.