{"id":"GHSA-p2j7-6g9h-32xh","summary":"Cross site scripting in Shopizer","details":"A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions v2.0.2 through v2.17.0 via the “Manage Images” tab, which allows an attacker to upload a SVG file containing malicious JavaScript code.","aliases":["CVE-2022-23059"],"modified":"2023-11-08T04:08:15.911976Z","published":"2022-03-30T00:00:27Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-04-07T22:06:36Z","nvd_published_at":"2022-03-29T11:15:00Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23059"},{"type":"WEB","url":"https://github.com/shopizer-ecommerce/shopizer/commit/6b9f1ecd303b3b724d96bd08095c1a751dcc287e"},{"type":"PACKAGE","url":"https://github.com/shopizer-ecommerce/shopizer"},{"type":"WEB","url":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-23059"}],"affected":[{"package":{"name":"com.shopizer:shopizer","ecosystem":"Maven","purl":"pkg:maven/com.shopizer/shopizer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.2"},{"fixed":"3.0.0"}]}],"versions":["2.16.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-p2j7-6g9h-32xh/GHSA-p2j7-6g9h-32xh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}