Cross-Site Scripting Vulnerability in Newbee-Mall by Newbee Ltd.
CVE-2022-27476
6.1MEDIUM
Summary
A security flaw exists in Newbee-Mall v1.0.0 that permits cross-site scripting (XSS) attacks. This vulnerability enables malicious users to inject and execute arbitrary web scripts or HTML in the context of the affected application. Specifically, an attacker can exploit this vulnerability through a crafted payload that is inserted into the goodsName parameter at the /admin/goods/update endpoint. This could potentially lead to unauthorized actions or data exposure.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved