Description
Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in the HTML output in the endpoint /product/. Exploitation of this vulnerability would allow an attacker to execute arbitrary JavaScript code.
Problem types
CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
Product status
latest demo version (custom)
Credits
Gonzalo Aguilar García (6h4ack)
References
www.incibe.es/.../multiple-vulnerabilities-cradle-e-commerce