Description
AbanteCart 1.2.12 has reflected cross-site scripting (XSS) via the sort parameter, as demonstrated by a /apparel--accessories?sort= substring.
Remediation
References
Related Vulnerabilities
TYPO3 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2005-4875)
Grafana Improper Authentication Vulnerability (CVE-2022-32276)
WordPress Plugin Blunt GA Cross-Site Scripting (4.0.0)
PostgreSQL Insufficient Verification of Data Authenticity Vulnerability (CVE-2024-10977)