Описание
osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of newsletters.
Ссылки
- Release NotesVendor Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- Release NotesVendor Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:oscommerce:oscommerce:2.3.4.1:*:*:*:*:*:*:*
EPSS
Процентиль: 65%
0.0049
Низкий
4.8 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
больше 3 лет назад
osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of newsletters.
EPSS
Процентиль: 65%
0.0049
Низкий
4.8 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79