Executive brief
Softtr E-Commerce Pack is a web-based e-commerce platform used to build and manage online stores. A cross-site scripting (XSS) vulnerability allows attackers to inject malicious scripts into web pages viewed by customers, potentially stealing login credentials, payment information, or session tokens without requiring any special access or authentication.
Technical details
This is a reflected or stored cross-site scripting (XSS) vulnerability stemming from improper neutralization of script-related HTML tags in user-supplied input. The vulnerable component fails to properly sanitize or encode HTML tags before rendering them in web pages. An attacker can inject malicious JavaScript code through crafted input (such as query parameters or form fields) that executes in the victim's browser within the context of the vulnerable application. No authentication is required, and the attack vector is network-based. Affected versions: E-Commerce Pack before 5.03.01.49. A patch is available in version 5.03.01.49 or later.
Affected products
- Softtr Informatics Technology Trading Limited E-Commerce Pack before 5.03.01.49
Timeline
- 2026-08-27: disclosed