Description
Isshue Shopping Cart 3.5 contains a persistent cross-site scripting vulnerability in title input fields across stock, customer, and invoice modules. Attackers with privileged user accounts can inject malicious scripts that execute on preview, potentially enabling session hijacking and persistent phishing attacks.
References
https://www.exploit-db.com/exploits/50490
ExploitThird Party Advisory
https://www.vulnerability-lab.com/get_content.php?id=2284
Third Party Advisory
https://www.exploit-db.com/exploits/50490
ExploitThird Party Advisory
https://www.vulnerability-lab.com/get_content.php?id=2284
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
7.2 · High
Information
Source identifier
Vulnerability status
Analyzed
Published
2026-01-15T16:16:08.507Z
1 month agoLast modified
2026-01-21T22:26:53.110Z
4 weeks ago