Description
PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the 'Comments / Special Instructions' parameter of the purchase page. Attackers can inject malicious JavaScript payloads that will execute when the page is refreshed, potentially allowing client-side script execution.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Anmol K Sachan
References
www.exploit-db.com/exploits/49574 (ExploitDB-49574)
web.archive.org/web/20210302174407/https://www.peel.fr/ (Archived Vendor Homepage)
www.vulncheck.com/...nstructions-stored-cross-site-scripting (VulnCheck Advisory: PEEL Shopping 9.3.0 - 'Comments/Special Instructions' Stored Cross-Site Scripting)