Cross-Site Scripting Vulnerability in Newbee-Mall by Newbee Ltd.
CVE-2022-27476
6.1MEDIUM
What is CVE-2022-27476?
A security flaw exists in Newbee-Mall v1.0.0 that permits cross-site scripting (XSS) attacks. This vulnerability enables malicious users to inject and execute arbitrary web scripts or HTML in the context of the affected application. Specifically, an attacker can exploit this vulnerability through a crafted payload that is inserted into the goodsName parameter at the /admin/goods/update endpoint. This could potentially lead to unauthorized actions or data exposure.
