Executive brief
A cross-site scripting (XSS) vulnerability exists in the Ecommerce-Website application's header menu component. An attacker can inject malicious code via the GET parameter "Error" in the /includes/header_menu.php file, which will be executed in users' browsers, potentially allowing credential theft, session hijacking, or malware distribution to customers.
Technical details
The vulnerability is a reflected cross-site scripting (XSS) flaw in the GET Parameter Handler component, specifically in /includes/header_menu.php where the "Error" parameter is insufficiently sanitized. An unauthenticated attacker can craft a malicious URL containing JavaScript payload in the Error parameter and trick users into clicking the link, causing the payload to execute in the victim's browser within the application context. The attack requires user interaction (clicking a link) and is remotely exploitable. A public exploit is available, though no patch from the vendor has been provided.
Affected products
- winston-dsouza Ecommerce-Website up to commit 87734c043269baac0b4cfe9664784462138b1b2e
Timeline
- 2025-11-30: disclosed
- other: Public exploit made available