CVE-2018-13001: Sandoba Cp::shop
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
An XSS issue was discovered in Sandoba CP:Shop v2016.1. The vulnerability is located in the `admin.php` file of the `./cpshop/` module. Remote attackers are able to inject their own script codes to the client-side requested vulnerable web-application parameters. The attack vector of the vulnerability is non-persistent and the request method to inject/execute is GET with the path, search, rename, or dir parameter.
Affected products
- Sandoba Cp::shop: version 2016.1 only
Published 2018-06-29. Last modified 2026-06-17.