Executive brief
Shopside App, an e-commerce management platform, contains a security vulnerability that could allow an attacker to inject malicious scripts into web pages. To exploit this, an attacker must already possess high-level administrative privileges within the application. If successful, this could lead to unauthorized actions being performed in the context of other users' sessions or the modification of displayed content.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in Shopside Software Shopside App due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability is reachable over the network but requires high privileges (PR:H) to exploit. An attacker with administrative access can inject malicious scripts that execute in the browser of other users. The issue was addressed in the update released on February 17, 2025.
Affected products
- Shopside Software Shopside App before 17.02.2025
Timeline
- 2025-02-17: patched: Vendor released fix for Shopside App
- 2025-09-17: disclosed: Initial advisory publication