Katyshop2 before 2.12 has multiple stored XSS issues.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.wizlynxgroup.com/security-research-advisories/vuln/WLX-2020-001 | third party advisory |
https://sourceforge.net/p/katyshop2/code/ci/8c6fb8d8df410e34b704e567805308d820ca5eae/ | third party advisory patch |