Medium severity6.1NVD Advisory· Published Jul 9, 2024· Updated Jun 17, 2026
CVE-2024-38963
CVE-2024-38963
Description
Nopcommerce 4.70.1 is vulnerable to Cross Site Scripting (XSS) via the combined "AddProductReview.Title" and "AddProductReview.ReviewText" parameter(s) (Reviews) when creating a new review.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4=4.70.1+ 1 more
- (no CPE)range: =4.70.1
- cpe:2.3:a:nopcommerce:nopcommerce:4.70.1:*:*:*:*:*:*:*
- Range: =4.70.1
- Nopcommerce/Nopcommercedescription
Patches
Vulnerability mechanics
References
2- github.com/nopSolutions/nopCommerce/issues/7224nvdExploitIssue TrackingVendor Advisory
- github.com/iamtron01/Vulnerability-Research/tree/main/CVE-2024-38963nvdThird Party Advisory
News mentions
0No linked articles in our index yet.