ShopXO header.html cross site scripting

CVE Details

Basic Information

Title ShopXO header.html cross site scripting
Type cve
Published 2025-07-14T03:14:05.401Z
Modified 2025-07-14T03:14:05.401Z

Product Information

Vendor n/a
Product ShopXO
Version 6.0

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description A cross-site scripting (XSS) vulnerability exists in ShopXO up to version 6.5.0. This vulnerability is caused by improper processing of the ‘lang/system_type’ argument in the header.html file, allowing remote attackers to inject malicious scripts.
AI Severity Medium
AI Vendor ShopXO Community
AI Product ShopXO
AI Version 6.5.0
AI Score 5.3

Affected Products

  • n/a ShopXO 6.0
  • n/a ShopXO 6.1
  • n/a ShopXO 6.2
  • n/a ShopXO 6.3
  • n/a ShopXO 6.4
  • n/a ShopXO 6.5.0

Additional Information

CWE List CWE-79, CWE-94
Source VulDB

Description

A vulnerability was found in ShopXO up to 6.5.0 and classified as problematic. This issue affects some unknown processing of the file header.html. The manipulation of the argument lang/system_type leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.