[Attack Vectors]
      > It was detected that a Stored XSS vulnerability on the "Currencies" 
functionality, specifically on the following input field: "Configuration > 
Currencies > Edit one of the currencies > "Custom formatting" input field. 
After saving the payload, the vulnerability can be triggered by visiting the 
following pages:
 - Bestsellers,
 - "Sales" > "Orders"
 - Also when someone views one of the products via the shop application the 
payload is triggered.

Assigned CVE code:
       > CVE-2025-65591

 [Discoverer]
      > AlterSec t/a PenTest.NZ


_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/

Reply via email to