6.1 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): CHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): NONE
Joomla VirtueMart Shopping-Cart 4.0.12 Reflected XSS via keyword
Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can craft malicious URLs containing script payloads in the keyword parameter of the product-variants endpoint to execute arbitrary JavaScript in victim browsers and steal session tokens or credentials.
References
-
ExploitDB-51631 exploit
-
Official Product Homepage product
-
Product Reference product
-
VulnCheck Advisory: Joomla VirtueMart Shopping-Cart 4.0.12 Reflected XSS via keyword third-party-advisory
Affected products
- ==4.0.12
Matching in nixpkgs
pkgs.carto
Mapnik stylesheet compiler
pkgs.cartero
Make HTTP requests and test APIs
pkgs.alacarte
Menu editor for GNOME using the freedesktop.org menu specification
pkgs.cartridges
GTK4 + Libadwaita game launcher
pkgs.perlPackages.Carton
Perl module dependency manager (aka Bundler for Perl)
pkgs.ocamlPackages.carton
Implementation of PACKv2 file in OCaml
pkgs.perl5Packages.Carton
Perl module dependency manager (aka Bundler for Perl)
pkgs.typstPackages.cartao
Dead simple, printable, flashcards with Typst
pkgs.perl538Packages.Carton
Perl module dependency manager (aka Bundler for Perl)
pkgs.perl540Packages.Carton
Perl module dependency manager (aka Bundler for Perl)
pkgs.python312Packages.cart
Python module for the CaRT Neutering format
pkgs.python313Packages.cart
Python module for the CaRT Neutering format
pkgs.python314Packages.cart
Python module for the CaRT Neutering format
pkgs.ocamlPackages.carton-git
Implementation of PACKv2 file in OCaml
pkgs.ocamlPackages.carton-lwt
Implementation of PACKv2 file in OCaml
pkgs.python312Packages.cartopy
Process geospatial data to create maps and perform analyses
pkgs.python313Packages.cartopy
Process geospatial data to create maps and perform analyses
pkgs.python314Packages.cartopy
Process geospatial data to create maps and perform analyses
pkgs.typstPackages.cartao_0_1_0
Dead simple flashcards with Typst
pkgs.typstPackages.cartao_0_2_0
Dead simple, printable, flashcards with Typst
pkgs.ocamlPackages_latest.carton
Implementation of PACKv2 file in OCaml
pkgs.ocamlPackages_latest.carton-git
Implementation of PACKv2 file in OCaml
pkgs.ocamlPackages_latest.carton-lwt
Implementation of PACKv2 file in OCaml
Package maintainers
-
@pluiedev Leah Amelia Chen <hi@pluie.me>
-
@Aleksanaa Aleksana QwQ <me@aleksana.moe>
-
@amerinor01 Alberto Merino <amerinor01@gmail.com>
-
@Luflosi Luflosi <luflosi@luflosi.de>
-
@getchoo Seth Flynn <getchoo@tuta.io>
-
@michaelgrahamevans Michael Evans <michaelgrahamevans@gmail.com>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@cherrypiejam Gongqi Huang
-
@sternenseemann Lukas Epple <sternenseemann@systemli.org>