CVE-2024-38963 Information

Description

Nopcommerce 4.70.1 is vulnerable to Cross Site Scripting (XSS) via the combined \AddProductReview.Title\ and \AddProductReview.ReviewText\ parameter(s) (Reviews) when creating a new review.

Reference

https://github.com/nopSolutions/nopCommerce/issues/7224 https://github.com/iamtron01/Vulnerability-Research/tree/main/CVE-2024-38963

Share on: