An issue was found in yii2_fecshop 2.x. There is a reflected XSS vulnerability in the check cart page.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/fecshop/yii2_fecshop/issues/87 | patch third party advisory exploit |
https://github.com/fecshop/yii2_fecshop/commit/8fac6455882333cfe3d81c4121d523813e28e31a | third party advisory patch |