Description
AbanteCart 1.2.12 has reflected cross-site scripting (XSS) via the sort parameter, as demonstrated by a /apparel--accessories?sort= substring.
Remediation
References
Related Vulnerabilities
MySQL CVE-2012-0494 Vulnerability (CVE-2012-0494)
Moodle Incorrect Authorization Vulnerability (CVE-2021-20282)
MyBB Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-2334)
WordPress Plugin Sell Photo Cross-Site Scripting (1.0.5)
CrushFTP Server URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-18288)