Metrics
Affected Vendors & Products
Sat, 28 Dec 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 27 Dec 2024 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in Beijing Longda Jushang Technology DBShop商城系统 3.3 Release 231225. It has been declared as problematic. This vulnerability affects unknown code of the file /home-order. The manipulation of the argument orderStatus with the input %22%3E%3Csvg%20onload=alert(5888)%3E leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | Beijing Longda Jushang Technology DBShop商城系统 home-order cross site scripting | |
Weaknesses | CWE-79 CWE-94 |
|
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-12-27T19:31:04.900Z
Updated: 2024-12-28T01:24:11.473Z
Reserved: 2024-12-27T08:48:02.599Z
Link: CVE-2024-12991
Updated: 2024-12-28T01:23:12.006Z
Status : Received
Published: 2024-12-27T20:15:22.140
Modified: 2024-12-27T20:15:22.140
Link: CVE-2024-12991
No data.