BootCommerce 3.2.1 contains persistent input validation vulnerabilities that allow remote attackers to inject malicious script code through guest order checkout input fields. Attackers can exploit unvalidated input parameters to execute arbitrary scripts, potentially leading to session hijacking, phishing attacks, and application module manipulation.
References
Configurations
No configuration.
History
03 Feb 2026, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.vulnerability-lab.com/get_content.php?id=2279 - |
Information
Published : 2026-02-01 13:15
Updated : 2026-02-03 17:15
NVD link : CVE-2022-50941
Mitre link : CVE-2022-50941
CVE.ORG link : CVE-2022-50941
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
