CVE-2021-26916

Publication date

2021-02-08 21:22:32

Family

mitre

State

PUBLISHED

Description

In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary web script or HTML through the Filters/CheckDiscountCouponAttribute.cs discountcode parameter.