Back

CVE-2002-0439

Cross-site scripting vulnerability in CaupoShop 1.30a and earlier, and possibly CaupoShopPro, allows remote attackers to execute arbitrary Javascript and steal credit card numbers or delete items by injecting the script into new customer information fields such as the message field.

Published: Jul 26, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
caupo.net cauposhop *

GitHub Security Advisory GHSA-2vrr-2g3v-v4gc

Cross-site scripting vulnerability in CaupoShop 1.30a and earlier, and possibly CaupoShopPro,...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.57%

Top 27% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub