4.7
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shopside Software Shopside App allows Cross-Site Scripting (XSS). This issue requires high privileges.This issue affects Shopside App: before 17.02.2025.
Basic Information
ID
CVE-2025-0879
Source
TR-CERT
Published
Sep 17, 2025 at 12:32
Affected Product
Vendor
Shopside Software
Product
Shopside App
Affected Versions
Shopside Software Shopside App 0