CVE-2026-5218: HTML Injection in Softtr's E-Commerce Pack
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Technology Trading Limited Company E-Commerce Pack allows Cross-Site Scripting (XSS).
This issue affects E-Commerce Pack: before 5.03.01.49.
Affected Software
Event History
Frequently Asked Questions
Which versions are affected?
E-Commerce Pack versions before 5.03.01.49 are affected. The provided information does not identify a specific fixed release beyond that version boundary.
What would an attacker need to exploit this issue?
The vector is network-based, requires no privileges, and has low attack complexity. However, exploitation requires user interaction, meaning a victim must interact with attacker-supplied or attacker-influenced content.
What is the likely security impact?
The issue is rated medium severity with a CVSS score of 4.3. It affects integrity but has no stated confidentiality or availability impact.