Cross-Site Scripting in newbee-mall 1.0 Add Category Page via categoryName
A serious vulnerability exists in newbee-mall 1.0 involving the Add Category Page component. The save function in the /admin/categories/save file is vulnerable to Cross Site Scripting (XSS) through manipulation of the categoryName argument. An attacker can launch this vulnerability remotely, and the exploit details have been publicly disclosed. Since newbee-mall uses a rolling release model for continuous delivery, specific version information for affected or patched releases is not available. The vulnerability allows potential harmful script injection, posing a security risk to the application.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
* newbee-mall |