Posted by Onur Tezcan via Fulldisclosure on Dec 15
[Attack Vectors]
> It was detected that a Stored XSS vulnerability in the Attributes management workflow. An attacker can insert
JavaScript into the Name field when adding a new Attribute Group (Catalog > Attributes > Specification attributes > Add
Group > Name input field). To exploit the vulnerability, privileged users should visit the “Specification attributes
page.
Assigned CVE code:
>…
– Read More – Full Disclosure



