Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ 1.20 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
| Software | From | Fixed in |
|---|---|---|
| elemental_software / cartwiz | 1.10 | 1.10.x |
| elemental_software / cartwiz | 1.20 | 1.20.x |