Unrated severityNVD Advisory· Published May 1, 2022· Updated Sep 16, 2024
Shopizer - Stored XSS in Manage Files
CVE-2022-23060
Description
A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged user (attacker) can inject malicious JavaScript in the filename under the “Manage files” tab
Affected products
1- Range: 2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/shopizer-ecommerce/shopizer/commit/6b9f1ecd303b3b724d96bd08095c1a751dcc287emitrex_refsource_MISC
- www.whitesourcesoftware.com/vulnerability-database/CVE-2022-23060mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.