CVE-2018-20848 – Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_aff …

Vuln ID: CVE-2018-20848

Published:  2019-06-30  19:15:09Z

Description: Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in the couleurId[0] parameter to the latter.

Source: NVD.NIST.GOV

 


Date:

Categorie(s):

Tag(s):