Impact
A cross‑site scripting vulnerability in the product_catalogue.php component of andrewtch88 MVC‑Ecommerce version 1.0 enables a remote attacker to inject arbitrary JavaScript into rendered pages. When the crafted script executes, it can cause the attacker to run code locally in the browser and may allow the attacker to read or modify sensitive information stored or displayed by the application. The impact includes compromise of confidentiality and integrity of data handled by the vulnerable component.
Affected Systems
The flaw affects the andrewtch88 MVC‑Ecommerce application, version 1.0, specifically the product_catalogue.php page. No additional platform or package information is provided.
Risk and Exploitability
The CVSS score is 6.1, indicating moderate severity. EPSS score of 0.00055 indicates a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog, so public exploitation rates are uncertain. The likely attack vector is a crafted HTTP request that includes malicious input targeting the product_catalogue.php endpoint, requiring network access to the web application.
OpenCVE Enrichment