Cross-site scripting vulnerability in Credit Card Payment Setup page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script in the page.
| Software | From | Fixed in |
|---|---|---|
| welcart / welcart_e-commerce | 2.7 | 2.8.21.x |