CVE-2022-28448

Published
View on NVD ↗
CVSS v3
5.4
MEDIUM
CVSS v2
3.5
LOW
Affected
1
PROJECT

Description

nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info.

ASP.NET Core eCommerce software. nopCommerce is a free and open-source shopping cart.
GitHubGitHub
10.1K