Cross-site scripting vulnerability in products1h.php in ESMI PayPal Storefront allows remote attackers to inject arbitrary web script or HTML via the id parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Paypal_storefront | Esmi | 1.7 (including) | 1.7 (including) |