nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payload fires.
References
| Link | Resource |
|---|---|
| http://nop.com | Not Applicable |
| http://nopcommerce.com | Product |
| https://cxsecurity.com/issue/WLB-2025100002 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-10-03 17:15
Updated : 2025-12-19 17:07
NVD link : CVE-2021-42193
Mitre link : CVE-2021-42193
CVE.ORG link : CVE-2021-42193
JSON object : View
Products Affected
nopcommerce
- nopcommerce
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
