Headline
jCart For OpenCart 3.0.3.19 Cross Site Scripting
jCart for OpenCart version 3.0.3.19 suffers from a cross site scripting vulnerability.
┌┌───────────────────────────────────────────────────────────────────────────────────────┐││ C r a C k E r ┌┘┌┘ T H E C R A C K O F E T E R N A L M I G H T ││└───────────────────────────────────────────────────────────────────────────────────────┘┘ ┌──── From The Ashes and Dust Rises An Unimaginable crack.... ────┐┌┌───────────────────────────────────────────────────────────────────────────────────────┐┌┘ [ Exploits ] ┌┘└───────────────────────────────────────────────────────────────────────────────────────┘┘: Author : CraCkEr :│ Website : extensions.joomla.org ││ Vendor : softPHP ││ Software : jCart for OpenCart 3.0.3.19 - Reflected XSS ││ jCart is a standalone Joomla ecommerce component which includes OpenCart ││ features ││ Vuln Type: Reflected XSS ││ Method : GET ││ Impact : Manipulate the content of the site ││ ││────────────────────────────────────────────────────────────────────────────────────────││ B4nks-NET irc.b4nks.tk #unix ┌┘└───────────────────────────────────────────────────────────────────────────────────────┘┘: :│ Release Notes: ││ ═════════════ ││ The attacker can send to victim a link containing a malicious URL in an email or ││ instant message can perform a wide variety of actions, such as stealing the victim's ││ session token or login credentials ││ │┌┌───────────────────────────────────────────────────────────────────────────────────────┐┌┘ ┌┘└───────────────────────────────────────────────────────────────────────────────────────┘┘Greets: The_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL CryptoJob (Twitter) twitter.com/CryptozJob ┌┌───────────────────────────────────────────────────────────────────────────────────────┐┌┘ © CraCkEr 2022 ┌┘└───────────────────────────────────────────────────────────────────────────────────────┘┘GET parameter 'Itemid' is vulnerable to XSShttp://demos.soft-php.com/jcart/index.php?option=com_jcart&Itemid=1091712';confirm(1)//274&route=product/search[-] Done