Sceawere

Vulnerability Detail

CVE-2026-66700UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Smart Online Order XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
7h ago
Vendor
ZAYTECH
Product
Smart Online Order for Clover
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-13T14:17:10.913Z",
  "pubdate": "2026-08-13T14:17:10.913Z",
  "executiveSummary": "An unauthenticated Cross-Site Scripting (XSS) vulnerability has been identified in the Smart Online Order for Clover plugin up to version 1.6.1. This security flaw permits remote attackers to inject arbitrary malicious client-side scripts, typically JavaScript, into web pages rendered to unsuspecting users. The primary impact of this vulnerability includes session hijacking, credential theft, sensitive data exposure, and unauthorized actions performed within the context of the victim's browser session. The affected system is the Smart Online Order for Clover software ecosystem operating on vulnerable version distributions. The risk implications are severe for site integrity and user trust, as exploitation requires no prior authentication or administrative privileges. The attacker capabilities are constrained only by the privileges of the interacting user viewing the injected content. Exploitation requirements are minimal, relying entirely on tricking a user into navigating to a crafted URL or interacting with maliciously formulated input parameters handled insecurely by the vulnerable plugin components without requiring any prior system access.",
  "technicalDetails": "The vulnerability resides in the input handling and output rendering mechanisms of the Smart Online Order for Clover plugin versions 1.6.1 and prior. The root cause stems from insufficient input sanitization and a lack of proper contextual output encoding for user-supplied data processed by the application. Specifically, HTTP request parameters containing malicious JavaScript or HTML payloads are accepted by vulnerable components and subsequently reflected back into the HyperText Markup Language (HTML) document returned to the client browser without adequate neutralization.\nNetwork exposure is fully external, as the application processes web requests directly over standard HTTP/HTTPS protocols from unauthenticated remote users. Because the vulnerability is unauthenticated, no valid user session, API keys, or privilege escalation sequences are necessary to deliver the exploit payload to the target endpoint. Attack flow initiates when an adversary crafts a malicious Uniform Resource Locator (URL) containing an executable JavaScript payload injected into vulnerable parameter fields or inputs processed by the plugin. When a victim visits the crafted URL or interacts with the compromised application feature, the server processes the request and embeds the unescaped payload directly into the response body.\nUpon receiving the HTTP response, the victim's browser parses the injected payload as legitimate application code rather than inert textual data. The payload behavior executes immediately within the Document Object Model (DOM) of the victim's active session, inheriting the security context, cookies, and local storage associated with the targeted web origin. Post-exploitation impact encompasses potential session token theft via document.cookie access, arbitrary DOM manipulation, redirection to malicious phishing portals, or the execution of unauthorized transactional actions on behalf of the authenticated user."
}
CVE-2026-66700: Smart Online Order XSS Vulnerability (HIGH Severity, CVSS: 7.1) - Sceawere