---
id: CVE-2022-35493
title: >-
  A Cross-site scripting (XSS) vulnerability in json search parse and the json
  response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version
  3.0.4 allows remote attackers to inject arbitrary web script or HTML via the
  get_pro…
summary: >-
  A Cross-site scripting (XSS) vulnerability in json search parse and the json
  response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version
  3.0.4 allows remote attackers to inject arbitrary web script or HTML via the
  get_pro…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
  - CWE-79
vendor: wrteam
product: eshop_-_ecommerce_/_store_website
affected:
  - eshop_-_ecommerce_/_store_website <= 3.0.4
published: '2022-08-08'
updated: '2026-07-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-35493'
references:
  - url: >-
      https://github.com/Keyvanhardani/Exploit-eShop-Multipurpose-Ecommerce-Store-Website-3.0.4-Cross-Site-Scripting-XSS/blob/main/README.md
    label: cve@mitre.org
  - url: >-
      https://github.com/Keyvanhardani/Exploit-eShop-Multipurpose-Ecommerce-Store-Website-3.0.4-Cross-Site-Scripting-XSS/blob/main/README.md
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.01696
epssPercentile: 0.76136
ingestedAt: '2026-07-08T17:51:52.306Z'
exploits:
  nuclei:
    - CVE-2022-35493
  checkedAt: '2026-09-25T08:20:40.919Z'
exploitAvailable: true
---

## Overview

A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the get_products?search parameter.

## Affected

- `eshop_-_ecommerce_/_store_website <= 3.0.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
