StarSea99 starsea-mall Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in StarSea99 starsea-mall version 1.0. The issue arises in the admin interface, specifically within the carousels save function. The vulnerability is caused by improper validation of the redirectUrl parameter, which allows attackers to inject malicious JavaScript that could be executed in the context of the user’s browser. This issue is classified under CWE-79, indicating a failure to properly sanitize user input before it is displayed to other users.
Impact
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the victim's browser.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
