Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ 1.20 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Cartwiz | Elemental_software | 1.10 (including) | 1.10 (including) |
| Cartwiz | Elemental_software | 1.20 (including) | 1.20 (including) |