Cross Site Scripting Vulnerability in mvc-ecommerce by Andrew Tch
CVE-2026-38939
6.1MEDIUM
What is CVE-2026-38939?
A Cross Site Scripting (XSS) vulnerability exists in the mvc-ecommerce product version 1.0, developed by Andrew Tch. This vulnerability allows remote attackers to execute arbitrary code by injecting malicious scripts through the product_catalogue.php component. Successful exploitation could lead to unauthorized access to sensitive information, which poses significant risks to users and their data. It is crucial for affected users to apply recommended patches to mitigate potential security threats.
