Security Advisory
CVE-2022-28448
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info.