lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <MEYP282MB2472B7A111E7B17DC72279AEA8AEA@MEYP282MB2472.AUSP282.PROD.OUTLOOK.COM>
Date: Fri, 12 Dec 2025 15:04:09 +0000
From: Onur Tezcan via Fulldisclosure <fulldisclosure@...lists.org>
To: "fulldisclosure@...lists.org" <fulldisclosure@...lists.org>
Subject: [FD] nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS)
 via the Currencies functionality.

 [Attack Vectors]
      > It was detected that a Stored XSS vulnerability on the "Currencies" functionality, specifically on the following input field: "Configuration > Currencies > Edit one of the currencies > "Custom formatting" input field. After saving the payload, the vulnerability can be triggered by visiting the following pages:
 - Bestsellers,
 - "Sales" > "Orders"
 - Also when someone views one of the products via the shop application the payload is triggered.

Assigned CVE code:
       > CVE-2025-65591

 [Discoverer]
      > AlterSec t/a PenTest.NZ


_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ