CVE-2025-13002

8.2

Farktor Software · E-Commerce Package

Farktor Software E-Commerce Package contains an improper neutralization of input during web page generation, leading to a stored or reflected cross-site scripting (XSS) vulnerability.

Executive summary

A high-severity cross-site scripting vulnerability in Farktor Software E-Commerce Package allows unauthenticated attackers to execute malicious scripts, potentially leading to unauthorized actions.

Vulnerability

This vulnerability is caused by improper input validation, categorized as CWE-79. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates that an unauthenticated attacker can trigger this flaw remotely without requiring user interaction.

Business impact

Successful exploitation of this vulnerability allows an attacker to inject arbitrary scripts into web pages viewed by other users. This can lead to the theft of session cookies, account takeover, or redirection to malicious websites, resulting in significant risk to customer data and organizational reputation. Given the CVSS score of 8.2, this flaw represents a high risk to the confidentiality and integrity of the web application.

Remediation

Immediate Action: Consult the official vendor security advisory for the availability of a security patch and apply it immediately to all affected instances.

Proactive Monitoring: Review web server access logs for anomalous request patterns, specifically looking for script-like characters or unusual URL parameters that deviate from standard application behavior.

Compensating Controls: Implement a robust Content Security Policy (CSP) and deploy a Web Application Firewall (WAF) configured to inspect and block malicious script injection attempts targeting your web application.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations utilizing the Farktor Software E-Commerce Package should prioritize this update as soon as the vendor makes a patch available. Due to the unauthenticated nature of the vulnerability, the potential for automated exploitation is high, and immediate monitoring of traffic is recommended until the underlying issue is resolved.

More Farktor Software CVEs

Sources

Originally found and disclosed by Berat ARSLAN, per the CVE Program record.