CVE-2018-1000887
Summary
| CVE | CVE-2018-1000887 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-28 16:29:00 UTC |
| Updated | 2021-02-22 18:45:00 UTC |
| Description | Peel shopping peel-shopping_9_1_0 version contains a Cross Site Scripting (XSS) vulnerability that can result in an authenticated user injecting java script code in the "Site Name EN" parameter. This attack appears to be exploitable if the malicious user has access to the administration account. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Peel | Peel Shopping | 9.1.0 | All | All | All |
| Application | Peel | Peel Shopping | 9.1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SOLVED: Stored Cross site Scripting in "Site Name EN" parameter · Issue #1 · advisto/peel-shopping · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.