Description
PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the address parameter of the change_params.php script. Attackers can inject malicious JavaScript payloads that execute when users interact with the address text box, potentially enabling client-side script execution.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Anmol K Sachan
References
www.exploit-db.com/exploits/49553
www.exploit-db.com/exploits/49553 (ExploitDB-49553)
web.archive.org/web/20210302174407/https://www.peel.fr/ (Archived Vendor Homepage)
www.vulncheck.com/...ing-address-stored-cross-site-scripting (VulnCheck Advisory: PEEL Shopping 9.3.0 - 'address' Stored Cross-Site Scripting)