Description
AbanteCart 1.2.12 has reflected cross-site scripting (XSS) via the sort parameter, as demonstrated by a /apparel--accessories?sort= substring.
Remediation
References
Related Vulnerabilities
WordPress Plugin S3Bubble Cloud Video With Adverts & Analytics Arbitrary File Download (0.7)
Drupal Improper Input Validation Vulnerability (CVE-2018-7600)
PostgreSQL Other Vulnerability (CVE-2007-0555)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17305)