Description
Cross-site scripting (XSS) vulnerability in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to inject arbitrary web script or HTML via the message parameter, probably involving the basket functionality.
Affected products
- apt / apt-webshop-system3.0 – 3.0
- apt / apt-webshop-system3.0 – 3.0
- apt / apt-webshop-system4.0 – 4.0