News:

AbanteCart v1.4.2 is released.

Main Menu

Do you like AbanteCart? Please rate AbanteCart or share your experience with other eCommerce entrepreneurs. Go to Softaculous rating page to add your rating or write a review

XSS Vulnerability

Started by Mahomed Dawood, December 09, 2021, 05:15:44 AM

Previous topic - Next topic

Mahomed Dawood

Hi Guys

I recently ran a security check on my website and came across some reflective xss vulnerability on the product page
Is this something that abantecart are planning on fixing ? or could this just be misconfiguration on my side ?

Basara

Hello.

Can you please tell us more about your findings?

Mahomed Dawood

Hi

So if i call my website

http://mywebsite/uri?keyword=10mm&category_id=%2522%253e%253cscript%253ealert%2528987654321%2529%253c%252fscript%253e

A pop up appears with a javascript

Please see attached


Basara



Mahomed Dawood


Basara

#6
Hello.
Thank you for reporting. We will provide the fix shortly
Please follow issue in the bug tracker https://github.com/abantecart/abantecart-src/issues/1513

Mahomed Dawood


Basara


Mahomed Dawood

Hi

Works like a charm

Thank you for your assistance

garyfartsalot

Hi Mahomed Dawood
How did you fix?
Did you update abantecart to latest fixed version or did you apply a fix?

llegrand

what cart version are you currently using?

We have posted the patch file for AbanteCart v 1.3.2 along with instructions
You can get it here:

https://why2central.net/patch/abantecart-v1-3-2-default-core-xss-vulnerability-patch-file/

If you are using v 1.3.3,  the corrected files are already in that code.


Forum Rules Code of conduct
AbanteCart.com 2010 -