Impact
The vulnerability is a reflected cross‑site scripting flaw caused by the omission of proper sanitization of the 'search' parameter in the product list endpoint. When an attacker sends a malicious payload via this parameter, the data is returned directly in the HTML response, allowing arbitrary JavaScript execution in the victim's browser. Based on the description, it is inferred that this could facilitate session hijacking, defacement, or phishing attacks against users who visit the compromised page.
Affected Systems
The flaw resides in the BeeTienda eCommerce Platform, specifically in the latest publicly available demo version. No precise release numbers are provided, and the issue has only been confirmed in the demo deployment. Consequently, any instance of BeeTienda that exposes the same search endpoint without proper input handling is potentially vulnerable.
Risk and Exploitability
The CVSS base score of 5.1 indicates moderate severity. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV. Because exploitation requires only a crafted query string, an unauthenticated attacker can easily trigger the flaw, but the impact is confined to the client’s browser context and does not affect the server state. The likely attack vector involves manipulating the search parameter and prompting a user to visit the malformed URL. There is no solution reported at this moment.
OpenCVE Enrichment