An issue was discovered in AbanteCart before 1.3.2. Any low-privileged user with file-upload permissions can upload a malicious SVG document that contains an XSS payload.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/abantecart/abantecart-src/releases | Release Notes Third Party Advisory | 
| https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-in-abantecart-e-commerce-platform/ | Exploit Third Party Advisory | 
Configurations
                    Information
                Published : 2021-12-14 07:15
Updated : 2021-12-15 14:17
NVD link : CVE-2021-42051
Mitre link : CVE-2021-42051
JSON object : View
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
                abantecart
- abantecart
 


