312
VMScore

CVE-2021-27190

Published: 12/02/2021 Updated: 07/12/2021
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

A Stored Cross Site Scripting(XSS) Vulnerability exists in PEEL SHOPPING 9.3.0 and 9.4.0, which are publicly available. The user supplied input containing polyglot payload is echoed back in javascript code in HTML response. This allows an malicious user to input malicious JavaScript which can steal cookie, redirect them to other malicious website, etc.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

peel peel shopping 9.3.0

peel peel shopping 9.4.0

Github Repositories

CVE-2021-27190 - PEEL Shopping, eCommerce shopping cart - Stored Cross-Site Scripting Vulnerability in 'Address' Date 2021-02-11 Exploit Author Anmol K Sachan Vendor Homepage wwwpeelfr/ Software Link wwwpeelfr/nos-offres-1/peel-shopping-31html sourceforgenet/projects/peel-shopping/ Vulnerable Software Link drivegooglecom/f