Security Advisory

CVE-2021-26916

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-02-08 21:22:32
Last updated 2024-08-03 20:33:41
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary web script or HTML through the Filters/CheckDiscountCouponAttribute.cs discountcode parameter.