Vulnerabilities
Vulnerable Software
Shopizer:  >> Shopizer  >> 2.17.0  Security Vulnerabilities
In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.
CVSS Score
8.8
EPSS Score
0.003
Published
2022-05-03
A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged user (attacker) can inject malicious JavaScript in the filename under the “Manage files” tab
CVSS Score
4.8
EPSS Score
0.002
Published
2022-05-01
In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Reference (IDOR) vulnerability.
CVSS Score
6.5
EPSS Score
0.003
Published
2022-05-01
A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0 via the “Manage Images” tab, which allows an attacker to upload a SVG file containing malicious JavaScript code.
CVSS Score
4.8
EPSS Score
0.002
Published
2022-03-29


Contact Us

Shodan ® - All rights reserved