Vulnerability Details CVE-2021-33561
A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via customer_name in various forms of store administration. It is saved in the database. The code is executed for any user of store administration when information is fetched from the backend, e.g., in admin/customers/list.html.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.6%
CVSS Severity
CVSS v3 Score 4.8
CVSS v2 Score 3.5
Products affected by CVE-2021-33561
-
cpe:2.3:a:shopizer:shopizer:1.1.5
-
cpe:2.3:a:shopizer:shopizer:2.0
-
cpe:2.3:a:shopizer:shopizer:2.0.1
-
cpe:2.3:a:shopizer:shopizer:2.0.2
-
cpe:2.3:a:shopizer:shopizer:2.0.2.1
-
cpe:2.3:a:shopizer:shopizer:2.0.3
-
cpe:2.3:a:shopizer:shopizer:2.0.4
-
cpe:2.3:a:shopizer:shopizer:2.0.5
-
cpe:2.3:a:shopizer:shopizer:2.0.6
-
cpe:2.3:a:shopizer:shopizer:2.10.0
-
cpe:2.3:a:shopizer:shopizer:2.11.0
-
cpe:2.3:a:shopizer:shopizer:2.13.0
-
cpe:2.3:a:shopizer:shopizer:2.14.0
-
cpe:2.3:a:shopizer:shopizer:2.14.1
-
cpe:2.3:a:shopizer:shopizer:2.15.0
-
cpe:2.3:a:shopizer:shopizer:2.16.0
-
cpe:2.3:a:shopizer:shopizer:2.2.0
-
cpe:2.3:a:shopizer:shopizer:2.3.0
-
cpe:2.3:a:shopizer:shopizer:2.4.0
-
cpe:2.3:a:shopizer:shopizer:2.5.0
-
cpe:2.3:a:shopizer:shopizer:2.6.0
-
cpe:2.3:a:shopizer:shopizer:2.7.0
-
cpe:2.3:a:shopizer:shopizer:2.8.0
-
cpe:2.3:a:shopizer:shopizer:2.9.0