XSS Vulnerability in E-Commerce Website by CP04042K
CVE-2022-27330
5.4MEDIUM
What is CVE-2022-27330?
A cross-site scripting (XSS) vulnerability exists in E-Commerce Website v1.0. This flaw allows attackers to execute arbitrary web scripts or HTML by injecting a malicious payload into the Product Title text field through the admin interface. Successful exploitation of this vulnerability can lead to compromised user sessions and unauthorized access to sensitive information.
