CVE-2021-33561

Description

A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via customer_name in various forms of store administration. It is saved in the database. The code is executed for any user of store administration when information is fetched from the backend, e.g., in admin/customers/list.html.

Risk Information

Base Score
4.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.734

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-33561,CVE-2021-33562 are fixed in Shopizer-shopizer 2.17.0Windows
Vulnerabilities CVE-2021-33561,CVE-2021-33562 are fixed in Shopizer-shopizer for Linux 2.17.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234