Vulnerability Description
Isshue Shopping Cart 3.5 contains a persistent cross-site scripting vulnerability in title input fields across stock, customer, and invoice modules. Attackers with privileged user accounts can inject malicious scripts that execute on preview, potentially enabling session hijacking and persistent phishing attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bdtask | Isshue | 3.5 |
Related Weaknesses (CWE)
References
- https://www.bdtask.com/multi-store-ecommerce-shopping-cart-software/Product
- https://www.exploit-db.com/exploits/50490ExploitThird Party Advisory
- https://www.vulnerability-lab.com/get_content.php?id=2284Third Party Advisory
- https://www.exploit-db.com/exploits/50490ExploitThird Party Advisory
- https://www.vulnerability-lab.com/get_content.php?id=2284Third Party Advisory
FAQ
What is CVE-2021-47769?
CVE-2021-47769 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Isshue Shopping Cart 3.5 contains a persistent cross-site scripting vulnerability in title input fields across stock, customer, and invoice modules. Attackers with privileged user accounts can inject ...
How severe is CVE-2021-47769?
CVE-2021-47769 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-47769?
Check the references section above for vendor advisories and patch information. Affected products include: Bdtask Isshue.