CVE-2021-32573
11.05.2021, 17:15
The express-cart package through 1.1.10 for Node.js allows Reflected XSS (for an admin) via a user input field for product options. NOTE: the vendor states that this "would rely on an admin hacking his/her own website.
Vendor | Product | Version |
---|---|---|
express-cart_project | express-cart | 𝑥 ≤ 1.1.10 |
𝑥
= Vulnerable software versions