{ "id": "CVE-2024-57277", "sourceIdentifier": "cve@mitre.org", "published": "2025-01-24T20:15:33.587", "lastModified": "2025-01-24T20:15:33.587", "vulnStatus": "Received", "cveTags": [], "descriptions": [ { "lang": "en", "value": "InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload." } ], "metrics": {}, "references": [ { "url": "https://github.com/innocommerce/innoshop/issues/115", "source": "cve@mitre.org" }, { "url": "https://github.com/yamerooo123/ResearchNBugBountyEncyclopedia/blob/main/Researches/Innocommerce/Findings.md", "source": "cve@mitre.org" }, { "url": "https://youtu.be/ved96wsIYlQ", "source": "cve@mitre.org" } ] }