CVE-2024-40746

CVSS V2 None CVSS V3 None
Description
A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload in the `description` parameter of any product. The `description `parameter is not sanitised in the backend.
Overview
  • CVE ID
  • CVE-2024-40746
  • Assigner
  • Joomla
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-10-21T16:16:32.627Z
  • Last Modified Date
  • 2024-10-21T16:46:05.894Z
References
Reference URL Reference Tags
https://www.hikashop.com/ product
History
Created Old Value New Value Data Type Notes
2024-10-22 13:09:34 Added to TrackCVE