CVE-2026-14634: Cross Site Scripting in kirilkirkov Ecommerce-CodeIgniter-Bootstrap
A vulnerability was identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e01394517. This vulnerability affects the function checkForPostRequests of the file application/core/MY_Controller.php of the component Subscribed Emails Admin Page. Such manipulation of the argument User-Agent leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and might be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The name of the patch is 23105f25dadf57b4314fc015a63a7c6e910c89df. It is advisable to implement a patch to correct this issue.
AI Analysis
Technical Summary
This vulnerability in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to commit 213babdbaa949e94557246414db0130e01394517 allows remote attackers to perform cross-site scripting via manipulation of the User-Agent header in the checkForPostRequests function of application/core/MY_Controller.php, impacting the Subscribed Emails Admin Page. The product follows a rolling release model, so no fixed version numbers are provided. A patch exists identified by commit 23105f25dadf57b4314fc015a63a7c6e910c89df. No known exploits in the wild have been reported.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary scripts in the context of the vulnerable web application by injecting malicious payloads through the User-Agent header. This can lead to user session hijacking, defacement, or other client-side attacks. The vulnerability requires user interaction (UI:P) and has no privileges or authentication required (PR:N). The overall impact is rated medium with a CVSS 4.0 score of 5.3.
Mitigation Recommendations
A patch is available for this vulnerability, identified by commit 23105f25dadf57b4314fc015a63a7c6e910c89df. It is advisable to apply this patch promptly to remediate the issue. Since the product uses a rolling release system, users should update to the latest version containing this patch. No vendor advisory was provided to indicate alternative mitigations or if the issue is already mitigated.
CVE-2026-14634: Cross Site Scripting in kirilkirkov Ecommerce-CodeIgniter-Bootstrap
Description
A vulnerability was identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e01394517. This vulnerability affects the function checkForPostRequests of the file application/core/MY_Controller.php of the component Subscribed Emails Admin Page. Such manipulation of the argument User-Agent leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and might be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The name of the patch is 23105f25dadf57b4314fc015a63a7c6e910c89df. It is advisable to implement a patch to correct this issue.
CVSS v4.0
Score 5.3medium
Affected software
cpe:2.3:a:kirilkirkov:ecommerce-codeigniter-bootstrap:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to commit 213babdbaa949e94557246414db0130e01394517 allows remote attackers to perform cross-site scripting via manipulation of the User-Agent header in the checkForPostRequests function of application/core/MY_Controller.php, impacting the Subscribed Emails Admin Page. The product follows a rolling release model, so no fixed version numbers are provided. A patch exists identified by commit 23105f25dadf57b4314fc015a63a7c6e910c89df. No known exploits in the wild have been reported.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary scripts in the context of the vulnerable web application by injecting malicious payloads through the User-Agent header. This can lead to user session hijacking, defacement, or other client-side attacks. The vulnerability requires user interaction (UI:P) and has no privileges or authentication required (PR:N). The overall impact is rated medium with a CVSS 4.0 score of 5.3.
Mitigation Recommendations
A patch is available for this vulnerability, identified by commit 23105f25dadf57b4314fc015a63a7c6e910c89df. It is advisable to apply this patch promptly to remediate the issue. Since the product uses a rolling release system, users should update to the latest version containing this patch. No vendor advisory was provided to indicate alternative mitigations or if the issue is already mitigated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-07-03T17:24:28.104Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a4936ab27e9c7971999f309
Added to database: 07/04/2026, 16:36:59 UTC
Last enriched: 07/12/2026, 08:51:26 UTC
Last updated: 08/18/2026, 22:49:25 UTC
Views: 105
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.