Description
Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can craft malicious URLs containing script payloads in the keyword parameter of the product-variants endpoint to execute arbitrary JavaScript in victim browsers and steal session tokens or credentials.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
CraCkEr
References
www.exploit-db.com/exploits/51631 (ExploitDB-51631)
www.virtuemart.net/ (Official Product Homepage)
demo.virtuemart.net/ (Product Reference)
www.vulncheck.com/...shopping-cart-reflected-xss-via-keyword (VulnCheck Advisory: Joomla VirtueMart Shopping-Cart 4.0.12 Reflected XSS via keyword)