VulnerabilityModified
CVE-2021-47769
Isshue Shopping Cart 3.5 contains a persistent cross-site scripting vulnerability in title input fields across stock, customer, and invoice modules.
MEDIUM 5.1EPSS 0.29%
Does this matter?
Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.
Description
Isshue Shopping Cart 3.5 contains a persistent cross-site scripting vulnerability in title input fields across stock, customer, and invoice modules. Attackers with privileged user accounts can inject malicious scripts that execute on preview, potentially enabling session hijacking and persistent phishing attacks.
- CVSS 4.0
- 5.1 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.29% probability · 22th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- bdtask/isshue
- Source
- disclosure@vulncheck.com
References
- https://www.bdtask.com/multi-store-ecommerce-shopping-cart-software/Product
- https://www.exploit-db.com/exploits/50490Exploit, Third Party Advisory
- https://www.vulnerability-lab.com/get_content.php?id=2284Third Party Advisory
- https://www.exploit-db.com/exploits/50490Exploit, Third Party Advisory
- https://www.vulnerability-lab.com/get_content.php?id=2284Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.