mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-28 18:48:49 +00:00
727 B
727 B
CVE-2024-57277
Description
InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload.
POC
Reference
- https://github.com/innocommerce/innoshop/issues/115
- https://github.com/yamerooo123/ResearchNBugBountyEncyclopedia/blob/main/Researches/Innocommerce/Findings.md
- https://youtu.be/ved96wsIYlQ