nopCommerce
cpe:2.3:a:nopcommerce:nopcommerce:*:*:*:*:*:*:*
- 4.90.0
A stored cross-site scripting vulnerability has been identified in nopCommerce version 4.90.0. This issue arises within the Attributes management workflow, where an attacker can inject JavaScript into the Name field while creating a new Attribute Group. The vulnerability requires a privileged user to access the 'Specification attributes' page to be exploited.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected page.
To reproduce this vulnerability, navigate to 'Catalog' > 'Attributes' > 'Specification attributes' and select 'Add Group'. In the Name input field, insert a JavaScript payload. Once the group is saved, the injected script will execute when the 'Specification attributes' page is accessed by a privileged user.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.