Posted by Onur Tezcan via Fulldisclosure on Dec 15
[Attack Vectors]
> It was detected that a Stored XSS vulnerability on the “Currencies” functionality, specifically on the
following input field: “Configuration > Currencies > Edit one of the currencies > “Custom formatting” input field.
After saving the payload, the vulnerability can be triggered by visiting the following pages:
– Bestsellers,
– “Sales” > “Orders”…
– Read More – Full Disclosure



