CVE-2022-28448

Publication date

2022-04-26 19:58:32

Family

mitre

State

PUBLISHED

Description

nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info.