A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions v2.0.2 through v2.17.0 via the “Manage Images” tab, which allows an attacker to upload a SVG file containing malicious JavaScript code.
{
"severity": "MODERATE",
"github_reviewed": true,
"nvd_published_at": "2022-03-29T11:15:00Z",
"cwe_ids": [
"CWE-79"
],
"github_reviewed_at": "2022-04-07T22:06:36Z"
}