Description
A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown function of the file xmall-manager-web/src/main/webapp/WEB-INF/jsp/order-print.jsp of the component Order Printing. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in the order‑print.jsp file of the Exrick xmall manager‑web component where user input is reflected Attackers can craft a malicious request that injects JavaScript into the print order page, allowing the execution of arbitrary client‑side code in the context of a logged‑in manager session. This reflected XSS can lead to session hijacking, credential theft, and unauthorized access to sensitive order data. The weakness is mapped to CWE‑79 for reflected XSS and CWE‑94 for unsafe evaluation of user data.

Affected Systems

The affected product is Exrick xmall. No specific version numbers are supplied; the last known vulnerable state is commit 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Because the project follows a rolling‑release model, newer releases may already contain a fix, but no official patch has been released yet.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact, while the EPSS score of < 1% suggests a low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog, leaving the overall risk moderate. Attackers can remotely exploit the flaw through the web interface by submitting crafted order‑printing requests, and any compromised user session will be vulnerable until a patch or mitigation is applied.

Generated by OpenCVE AI on September 15, 2026 at 17:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Exrick xmall to the latest commit or release that removes the unvalidated input in order‑print.jsp; if no such release exists, request a fix from the maintainers.
  • Implement server‑side input validation and HTML entity encoding for all data rendered in order‑print.jsp to prevent script execution.
  • Deploy a web‑application firewall rule or employ content‑security‑policy headers that block the injection of JavaScript into the order‑printing page.

Generated by OpenCVE AI on September 15, 2026 at 17:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown function of the file xmall-manager-web/src/main/webapp/WEB-INF/jsp/order-print.jsp of the component Order Printing. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.
Title Exrick xmall Order Printing order-print.jsp cross site scripting
First Time appeared Exrick
Exrick xmall
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:exrick:xmall:*:*:*:*:*:*:*:*
Vendors & Products Exrick
Exrick xmall
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T15:26:12.923Z

Reserved: 2026-09-12T16:06:41.575Z

Link: CVE-2026-90571

cve-icon Vulnrichment

Updated: 2026-09-14T15:26:06.177Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T17:16:58.157

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90571

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')