A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions v2.0.2 through v2.17.0 via the “Manage Images” tab, which allows an attacker to upload a SVG file containing malicious JavaScript code.
{ "nvd_published_at": "2022-03-29T11:15:00Z", "github_reviewed_at": "2022-04-07T22:06:36Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-79" ] }