Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, and interface/registercustomer/onlineregfailure.php.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://cxsecurity.com/issue/WLB-2018120091 | third party advisory exploit |
https://seclists.org/fulldisclosure/2014/Aug/8 | third party advisory mailing list |
https://www.exploit-db.com/exploits/46549/ | exploit vdb entry third party advisory |