SecBoard
Zurück zur CVE-Übersicht

CVE-2025-66572

NONE
Risk Signal Score0/100 — NIEDRIG

EPSS-Score

0%

Exploit-Wahrscheinlichkeit (30 Tage)

Beschreibung

Loaded Commerce 6.6 contains a client-side template injection vulnerability via the search parameter that allows unauthenticated attackers to execute arbitrary code in the victim's browser context when they visit a crafted URL.

Referenzen