Security Advisory

CVE-2022-35493

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-08-08 14:10:51
Last updated 2026-07-08 16:13:50
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the get_products?search parameter.