Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/bagisto/bagisto/pull/9474 | issue tracking |
https://github.com/Ek-Saini/security/blob/main/xss-bagisto-v1.5.1 | third party advisory exploit |