CVE-2022-23059
EUVD-2022-148629.03.2022, 11:15
A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0 via the “Manage Images” tab, which allows an attacker to upload a SVG file containing malicious JavaScript code.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| shopizer | shopizer | 2.0 ≤ 𝑥 ≤ 2.17.0 |
𝑥
= Vulnerable software versions
References