CVE-2022-21149
Summary
| CVE | CVE-2022-21149 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-01 16:15:00 UTC |
| Updated | 2022-05-11 13:57:00 UTC |
| Description | The package s-cart/s-cart before 6.9; the package s-cart/core before 6.9 are vulnerable to Cross-site Scripting (XSS) which can lead to cookie stealing of any victim that visits the affected URL so the attacker can gain unauthorized access to that user's account through the stolen cookie. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cross-site Scripting (XSS) in s-cart/core | CVE-2022-21149 | Snyk | MISC | snyk.io | |
| Cross-site Scripting (XSS) in s-cart/s-cart | CVE-2022-21149 | Snyk | MISC | snyk.io | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Faisal Fs
There are currently no legacy QID mappings associated with this CVE.