CVE-2021-27190
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
A Stored Cross Site Scripting(XSS) Vulnerability was discovered in PEEL SHOPPING 9.3.0 and 9.4.0, which are publicly available. The user supplied input containing polyglot payload is echoed back in javascript code in HTML response. This allows an attacker to input malicious JavaScript which can steal cookie, redirect them to other malicious website, etc.
Se detectó una vulnerabilidad de Cross Site Scripting(XSS) almacenada en PEEL SHOPPING versiones 9.3.0 y 9.4.0, que están disponibles públicamente. La entrada suministrada por el usuario que contiene la carga útil de políglota se devuelve en código javascript en la respuesta HTML. Esto permite a un atacante introducir código javascript malicioso que puede robar la cookie, redirigirla a otro sitio web malicioso, etc
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-02-10 CVE Reserved
- 2021-02-12 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-10-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/advisto/peel-shopping/issues/4#issuecomment-953461611 | 2021-12-07 |
URL | Date | SRC |
---|---|---|
https://www.peel-shopping.com/modules/telechargement/telecharger.php?id=7 | 2021-12-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Peel Search vendor "Peel" | Peel Shopping Search vendor "Peel" for product "Peel Shopping" | 9.3.0 Search vendor "Peel" for product "Peel Shopping" and version "9.3.0" | - |
Affected
| ||||||
Peel Search vendor "Peel" | Peel Shopping Search vendor "Peel" for product "Peel Shopping" | 9.4.0 Search vendor "Peel" for product "Peel Shopping" and version "9.4.0" | - |
Affected
|