Impact
Ecommerce Fruits Bazar 1.0 contains a Cross‑Site Scripting vulnerability in the admin/edit_product.php page. The flaw allows malicious JavaScript to be injected into the page, which is then executed when the page is rendered in a user's browser. This can lead to credential theft, unauthorized actions, defacement, or data exfiltration in the context of the victim user.
Affected Systems
All installations of Ecommerce Fruits Bazar version 1.0 that expose the admin/edit_product.php endpoint are affected. The product is a web‑based e‑commerce platform with an administrative interface for product management.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. The EPSS score of < 1% shows a low probability of exploitation at this time, and the vulnerability is not listed in CISA KEV. The likely attack vector is an authenticated administrator who can navigate to the vulnerable page, or an unauthenticated user if the admin interface is exposed externally. In either case, a successful payload would execute in the victim’s browser and could compromise the user’s session, steal credentials, or deface the application.
OpenCVE Enrichment