S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-35493 Scanner

CVE-2022-35493 scanner - Cross-Site Scripting (XSS) vulnerability in eShop - Multipurpose Ecommerce Store Website

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-35493
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the get_products?search parameter.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The eShop - Multipurpose Ecommerce Store Website version 3.0.4 is a popular e-commerce solution used by online retailers to build their digital storefronts. Its versatility allows retailers to cater to various needs, such as different modes of payment, customization options, and product offerings. The software's user-friendly interface and quick-to-deploy functionalities make it a go-to choice for small to medium-sized businesses seeking to expand their online presence.

However, a recent vulnerability CVE-2022-35493 was detected in the product that put users at risk. This vulnerability stemmed from the json search parse and the json response in wrteam.in, which allowed remote attackers to inject arbitrary web script or HTML via the get_products?search parameter. In simpler terms, hackers could potentially input malicious code messages into search forms and gain access to sensitive customer information or even control the website.

In the hands of malicious actors, the exploitation of this vulnerability could lead to a range of devastating consequences. For instance, e-commerce shoppers could have their personal and financial information compromised, leading to unauthorized purchases, identity theft, or fraudulent activities. This could ultimately lead to a loss of trust in the retailer and a tarnished reputation.

In conclusion, vulnerabilities like CVE-2022-35493 can have detrimental effects on any e-commerce business, and it's crucial to be proactive in protecting against them. At s4e.io, we offer robust security solutions that help online businesses identify, remediate, and shield against vulnerabilities like this one. As a result, users can rest assured that their digital assets are safe from any potential threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, several precautions can be taken. Here is a bullet point list of best practices to follow:

  • Update the eShop application and any third-party add-ons to the latest version.
  • Implement regular security scans and penetration testing to identify and resolve vulnerabilities before attackers can exploit them.
  • Use input validation to sanitize user input data to ensure that only expected and safe data is passed into the system.
  • Employ server-side input filtering to capture potentially harmful input requests that could inject malicious code or data.
  • Implement proper access control measures to allow only authorized access to sensitive data and systems.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-35493 scanner - Cross-Site Scripting (XSS) vulnerability in eShop - Multipurpose Ecommerce Store Website S4E