[<prev] [next>] [day] [month] [year] [list]
Message-ID: <MEYP282MB2472AA1BC0338B163D54C3F5A8AEA@MEYP282MB2472.AUSP282.PROD.OUTLOOK.COM>
Date: Fri, 12 Dec 2025 15:07:24 +0000
From: Onur Tezcan via Fulldisclosure <fulldisclosure@...lists.org>
To: "fulldisclosure@...lists.org" <fulldisclosure@...lists.org>
Subject: [FD] nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS)
in the product management functionality
[Attack Vectors]
> It was detected that multiple Stored Cross-Site Scripting (Stored XSS) vulnerabilities in the product management functionality. Malicious JavaScript payloads inserted into the "Product Name" and "Short Description" fields are stored in the backend database and executed automatically whenever a user (administrator or customer) views the affected pages.
Assigned CVE code:
> CVE-2025-65592
[Discoverer]
> AlterSec t/a PenTest.NZ
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/
Powered by blists - more mailing lists