Impact
Shopclass before 6.2.0 contains a stored cross‑site scripting flaw that allows any self‑registered non‑admin user to inject JavaScript into the item listing description field when the frontend TinyMCE editor is enabled. The vulnerability arises because ItemActions.php accepts the description without stripping HTML tags, so malicious code is persisted to the database and executed in the browser of any visitor who views the affected listing, potentially leaking cookies, defacing the site, or redirecting users to malicious sites. This failure to properly sanitize user input is a classic input‑validation weakness (CWE‑79) and can compromise confidentiality, integrity, and availability of the site.
Affected Systems
The affected vendor is Mindstellar, product Shopclass. Any installed version before 6.2.0 is vulnerable. The problem exists only when the TinyMCE editor is active and users can submit listing descriptions.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog, suggesting no widespread exploitation is reported. The attack vector is local to the application: an attacker must register an account on the site and submit a crafted listing description. Once submitted, the injected JavaScript is stored and will run in the context of the site origin whenever the listing is viewed, providing a non‑privileged code‑execution path for cross‑site attacks.
OpenCVE Enrichment