A Stored Cross Site Scripting(XSS) Vulnerability was discovered in PEEL...
Vulnerability Description
A Stored Cross Site Scripting(XSS) Vulnerability was discovered in PEEL SHOPPING 9.3.0 and 9.4.0, which are publicly available. The user supplied input containing polyglot payload is echoed back in javascript code in HTML response. This allows an attacker to input malicious JavaScript which can steal cookie, redirect them to other malicious website, etc.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-27190
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.peel-shopping.com/modules/telechargement/telecharger.php?id=7
- https://www.secuneus.com/cve-2021-27190-peel-shopping-ecommerce-shopping-cart-stored-cross-site-scripting-vulnerability-in-address/
- https://github.com/anmolksachan/CVE-2021-27190-PEEL-Shopping-cart-9.3.0-Stored-XSS
- https://github.com/vulf/Peel-Shopping-cart-9.4.0-Stored-XSS
- https://github.com/advisto/peel-shopping/issues/4#issuecomment-953461611
More from peel
View All →Affected Vendor
peel
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.