Cross-Site Scripting Vulnerability in Newbee-Mall by Newbee Ltd.
CVE-2022-27476

6.1MEDIUM

Key Information:

Vendor
CVE Published:
10 April 2022

Summary

A security flaw exists in Newbee-Mall v1.0.0 that permits cross-site scripting (XSS) attacks. This vulnerability enables malicious users to inject and execute arbitrary web scripts or HTML in the context of the affected application. Specifically, an attacker can exploit this vulnerability through a crafted payload that is inserted into the goodsName parameter at the /admin/goods/update endpoint. This could potentially lead to unauthorized actions or data exposure.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-27476 : Cross-Site Scripting Vulnerability in Newbee-Mall by Newbee Ltd. | SecurityVulnerability.io