Home
MEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:NDefault status
unaffected
6.6
affected
Description
Loaded Commerce 6.6 contains a client-side template injection vulnerability that allows unauthenticated attackers to execute code on the server via the search parameter.
Problem types
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
6.6
Credits
tmrswrr
References
www.exploit-db.com/exploits/52084 (ExploitDB-52084)
loadedcommerce.com/ (Loaded Commerce Homepage)
www.vulncheck.com/...e-66-client-side-template-injectioncsti