Cross-Site Scripting Vulnerability in Exrick xmall Order Printing Component
CVE-2026-90571
5.3MEDIUM
What is CVE-2026-90571?
A Cross-Site Scripting vulnerability exists in the Order Printing component of Exrick xmall, specifically in the order-print.jsp file. This vulnerability allows attackers to execute arbitrary scripts in the context of a user's browser by manipulating the output rendered by this function. The potential for remote exploitation raises serious security concerns, especially considering that the project has not yet provided a patch or response following the early notification of this failure. Users should take immediate precautions to mitigate risks associated with this vulnerability.
Affected Version(s)
xmall 19e7917d5ed3bd2a2421a3a246ad494c133ba94c
