CVE-2018-7465
26.04.2018, 19:29
An XSS issue was discovered in VirtueMart before 3.2.14. All the textareas in the backend of the plugin can be closed by simply adding </textarea> to the value and saving the product/config. By editing back the product/config, the editor's browser will execute everything after the </textarea>, leading to a possible XSS.
Vendor | Product | Version |
---|---|---|
virtuemart | virtuemart | 𝑥 < 3.2.14 |
𝑥
= Vulnerable software versions
References