Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the onMouseOver event of an A tag in a review message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Comdev_ecommerce | Comdev | 3.0 (including) | 3.0 (including) |
Comdev_ecommerce | Comdev | 3.1 (including) | 3.1 (including) |