Stored Cross-Site Scripting in PEEL Shopping by Peel
CVE-2021-47897
Key Information:
- Vendor
Peel Ecommerce
- Status
- Vendor
- CVE Published:
- 23 January 2026
Badges
What is CVE-2021-47897?
PEEL Shopping version 9.3.0 is vulnerable to a stored cross-site scripting flaw in the address parameter of the change_params.php script. This security issue allows attackers to inject malicious JavaScript into the address text box, which can be executed when users interact with the affected form. The exploitation of this vulnerability could lead to unauthorized script execution in users' browsers, potentially compromising sensitive data and user sessions.
Affected Version(s)
PEEL Shopping 9.3.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
