VulnerabilityModified
CVE-2018-7465
An XSS issue was discovered in VirtueMart before 3.2.14.
MEDIUM 5.4EPSS 2.29%
Does this matter?
Lower severity and a low EPSS score (2.29%). Track it; it rarely justifies an emergency change on its own.
Description
An XSS issue was discovered in VirtueMart before 3.2.14. All the textareas in the backend of the plugin can be closed by simply adding </textarea> to the value and saving the product/config. By editing back the product/config, the editor's browser will execute everything after the </textarea>, leading to a possible XSS.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 2.29% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- virtuemart/virtuemart
- Source
- cve@mitre.org
References
- http://virtuemart.net/news/489-virtuemart-3-2-14-security-release-and-enhanced-invoice-handlingVendor Advisory
- https://imgur.com/a/Hf6JDExploit, Third Party Advisory
- https://www.exploit-db.com/exploits/44625/Exploit, Third Party Advisory, VDB Entry
- http://virtuemart.net/news/489-virtuemart-3-2-14-security-release-and-enhanced-invoice-handlingVendor Advisory
- https://imgur.com/a/Hf6JDExploit, Third Party Advisory
- https://www.exploit-db.com/exploits/44625/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.