Reflected XSS Vulnerability in Robokassa Payment Gateway for Woocommerce
CVE-2024-47395

7.1HIGH

What is CVE-2024-47395?

A reflected cross-site scripting (XSS) vulnerability exists in the Robokassa payment gateway for WooCommerce, impacting versions from n/a up to 1.6.1. This flaw arises from improper neutralization of input during web page generation, allowing malicious actors to inject arbitrary scripts into web pages viewed by users. This could potentially lead to unauthorized data access, session hijacking, or the delivery of malware. Website administrators using the affected versions of this plugin should take immediate precautions to mitigate risks associated with this vulnerability.

Affected Version(s)

Robokassa payment gateway for Woocommerce <= 1.6.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dimas Maulana (Patchstack Alliance)
.