Impact
The vulnerability resides in the /index.php/api/product/set endpoint of the ECommerce‑CodeIgniter‑Bootstrap application. Attackers can alter the title or description parameters to inject arbitrary JavaScript into the response. When a victim’s browser renders the response,, enabling session hijacking, defacement, or other client‑side actions. The flaw is an input‑validation weakness (CWE‑79).
Affected Systems
All iterations of the kirilkirkov ECommerce‑CodeIgniter‑Bootstrap platform preceding commit d9785f995da77bdc62fb2d34bad5f7a162c9ad23 are affected. Because the project implements a rolling‑release model, no specific version numbers can be listed; the only reliable mitigation is to deploy the latest code containing the commit-based patch. The product’s continuous delivery cycle means every new commit after the patch includes remediation, so pending releases are not vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, while the EPSS score of < 1% non‑zero probability of exploitation. The vulnerability is not listed in CISA KEV, suggesting it has not yet been widely confirmed in the wild. The attack vector is remote; the description does not explicitly state whether authentication is required to reach the endpoint, so the possibility of unauthenticated access is uncertain.
OpenCVE Enrichment