Executive brief
SourceCodester SUP Online Shopping is an e-commerce platform. A security flaw in the administrative product management interface allows an attacker to inject malicious scripts into product names. If an administrator views the affected product page, the script could execute, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in SourceCodester SUP Online Shopping 1.0 within the /admin/productedit.php component. The vulnerability is caused by insufficient sanitization of the 'productName' POST parameter before it is stored and subsequently rendered in the web interface. A remote attacker with high privileges (administrative access) can submit a crafted product name containing malicious JavaScript. When other users or administrators view the edited product details, the script executes in their browser context. This can lead to session hijacking via cookie theft or unauthorized actions performed on behalf of the victim. A public exploit (PoC) is available.
Affected products
- SourceCodester SUP Online Shopping 1.0
Timeline
- 2026-04-21: disclosed: Initial disclosure on GitHub by redshadowword-cell
- 2026-05-24: advisory: NVD publication date