CodeAstro Ecommerce Website
cpe:2.3:a:codeastro:ecommerce_website:*:*:*:*:*:*:*
- 1.0
A stored cross-site scripting vulnerability has been identified in CodeAstro Ecommerce Website version 1.0. The issue resides in the 'Edit Your Account' page, specifically within the 'my_account.php' file. The vulnerability allows for the injection of malicious scripts into the 'Username' field, which are then executed in the context of other users' browsers when the username is displayed. This exploitation can be initiated remotely.
Exploitation of this vulnerability allows for the execution of injected JavaScript in the affected user's browser, potentially leading to session hijacking, account takeover, and other malicious actions such as phishing or UI defacement.
To reproduce this vulnerability, log into an account and navigate to the 'Edit Account' section. Inject a script payload into the 'Customer Name' field and save the changes. After logging out and back in, the injected script will execute on the home page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.