Cross-Site Scripting Vulnerability in Ecommerce-CodeIgniter-Bootstrap
CVE-2021-40975
6.1MEDIUM
Key Information:
- Vendor
- CVE Published:
- 1 October 2021
What is CVE-2021-40975?
A cross-site scripting vulnerability exists in the Ecommerce-CodeIgniter-Bootstrap application that allows remote attackers to inject arbitrary web scripts or HTML via the 'search_title' parameter located in the products.php file. This exploitation can potentially lead to unauthorized actions or data exposure, emphasizing the necessity for immediate assessment and mitigation strategies for affected versions.