CVE-2018-1000887
Last modified
CVE-2018-1000887 is a vulnerability of currently unknown severity. Peel shopping peel-shopping_9_1_0 version contains a Cross Site Scripting (XSS) vulnerability that can result in an authenticated user injecting java script code in the "Site Name EN" parameter. This attack appears to be exploitable if the malicious user has access to the administration account.. EPSS estimates a 0.67% chance of exploitation in the next 30 days.
Description
Peel shopping peel-shopping_9_1_0 version contains a Cross Site Scripting (XSS) vulnerability that can result in an authenticated user injecting java script code in the "Site Name EN" parameter. This attack appears to be exploitable if the malicious user has access to the administration account.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Peel | Peel Shopping | 9.1.0 |
References
- https://github.com/advisto/peel-shopping/issues/1Exploit, Third Party Advisory
- https://github.com/advisto/peel-shopping/issues/1Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1000887?
How severe is CVE-2018-1000887?
How do I fix CVE-2018-1000887?
Are you affected by CVE-2018-1000887?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
