CVE-2021-33562

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-33562
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-33562.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-33562
Aliases
Published
2021-05-24T23:15:08Z
Modified
2024-10-12T07:40:15.759782Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via the ref parameter to a page about an arbitrary product, e.g., a product/insert-product-name-here.html/ref= URL.

References

Affected packages

Git / github.com/shopizer-ecommerce/shopizer

Affected ranges

Type
GIT
Repo
https://github.com/shopizer-ecommerce/shopizer
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

2.*

2.13.0
2.14.1
2.15.0
2.16.0

v2.*

v2.13.0
v2.14.0
v2.14.1