CVE-2024-40746
A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web brows…
MEDIUM
HikaShop
Composant
Source officielle
Description
A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload in the `description` parameter of any product. The `description `parameter is not sanitised in the backend.
Sévérité
5.4
Moyenne · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | MEDIUM | 5.4 (v3.1) |
Produit et versions
- Produit
- HikaShop
- Type
- Composant
- Corrigée dans
- 5.1.1
- Publiée
- 21/10/2024
- Modifiée
- 17/06/2026
- CWE
- CWE-79
Versions concernées
- com_osticky — 1.0.0 – 5.1.0
- hikashop — jusqu'à 5.1.1 (exclue)
Sources
- NVD CNA Joomla CVE-2024-40746 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC