Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e11b83ef7.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://huntr.dev/bounties/9d308ebb-4289-411f-ac22-990383d98932 | issue tracking exploit |
https://github.com/saleor/react-storefront/commit/c29aab226f07ca980cc19787dcef101e11b83ef7 | patch |