nopSolutions / nopCommerce

ASP.NET Core eCommerce software. nopCommerce is a free and open-source shopping cart.
https://www.nopcommerce.com
Other
9.08k stars 5.19k forks source link

Updated XSS Vulnerability #7224

Closed iamtron01 closed 3 weeks ago

iamtron01 commented 3 weeks ago

nopCommerce version: 4.70.1

Good day,

Steps to reproduce the problem:

  1. Download Nop Commerce 4.70.1 with Source Code
  2. Open Solution in Visual Studio, 2022
  3. Run Solution and go through setup wizard, include sample data
  4. Login as a customer
  5. Click on a product
  6. Click Add your review
  7. For Review title enter,
  8. For Review text enter,
  9. Click Submit Review

Please acknowledge

See attachments: Popup, request/response from Nop 4.70.1, request/response from Nop 4.70.2 Popup Nop_Commerce_Request_Response_Post_Review_4_70_1 Nop_Commerce_Request_Response_Post_Review_4_7_2

AndreiMaz commented 3 weeks ago

@iamtron01 Thanks a lot for reporting. You're right. We've already fixed it in the mentioned commit