We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-5766

Likeshop Merchandise admin cross site scripting



Description

EN DE

A vulnerability was found in Likeshop up to 2.5.7 and classified as problematic. This issue affects some unknown processing of the file /admin of the component Merchandise Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-267449 was assigned to this vulnerability.

Eine problematische Schwachstelle wurde in Likeshop bis 2.5.7 gefunden. Hierbei geht es um eine nicht exakt ausgemachte Funktion der Datei /admin der Komponente Merchandise Handler. Mittels Manipulieren mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk.

Reserved 2024-06-07 | Published 2024-06-08 | Updated 2024-09-03 | Assigner VulDB


MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
LOW: 2.4CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
LOW: 2.4CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
3.3AV:N/AC:L/Au:M/C:N/I:P/A:N

Problem types

CWE-79 Cross Site Scripting

Timeline

2024-06-07:Advisory disclosed
2024-06-07:VulDB entry created
2024-06-07:VulDB entry last update

Credits

VulDB Gitee Analyzer tool

References

vuldb.com/?id.267449 (VDB-267449 | Likeshop Merchandise admin cross site scripting) vdb-entry

vuldb.com/?ctiid.267449 (VDB-267449 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

gitee.com/likeshop_gitee/likeshop/issues/I9TAHP issue-tracking

cve.org (CVE-2024-5766)

nvd.nist.gov (CVE-2024-5766)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-5766

Support options

Helpdesk Chat, Email, Knowledgebase