Sellacious eCommerce 4.6 contains a persistent cross-site scripting vulnerability in the Manage Your Addresses module that allows attackers to inject malicious scripts. Attackers can exploit multiple address input fields like full name, company, and address to execute persistent script code that can hijack user sessions and manipulate application modules.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sellacious
Sellacious ecommerce |
|
| Vendors & Products |
Sellacious
Sellacious ecommerce |
Fri, 30 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 Jan 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sellacious eCommerce 4.6 contains a persistent cross-site scripting vulnerability in the Manage Your Addresses module that allows attackers to inject malicious scripts. Attackers can exploit multiple address input fields like full name, company, and address to execute persistent script code that can hijack user sessions and manipulate application modules. | |
| Title | Sellacious eCommerce 4.6 - Persistent Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-01-30T16:16:38.301Z
Updated: 2026-01-30T16:31:36.265Z
Reserved: 2026-01-27T15:47:08.000Z
Link: CVE-2020-37003
Updated: 2026-01-30T16:31:32.926Z
Status : Received
Published: 2026-01-30T17:16:10.970
Modified: 2026-01-30T17:16:10.970
Link: CVE-2020-37003
No data.