Posted by Onur Tezcan via Fulldisclosure on Dec 15
[Attack Vectors]
> It was detected that multiple Stored Cross-Site Scripting (Stored XSS) vulnerabilities in the product
management functionality. Malicious JavaScript payloads inserted into the “Product Name” and “Short Description” fields
are stored in the backend database and executed automatically whenever a user (administrator or customer) views the
affected pages.
Assigned CVE code:
…
– Read More – Full Disclosure



