vendor:
osCommerce
by:
Emre Aslan
7.5
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: osCommerce
Affected Version From: 2.3.4.1
Affected Version To: 2.3.4.1
Patch Exists: NO
Related CWE:
CPE: a:oscommerce:oscommerce:2.3.4.1
Platforms Tested: Windows & XAMPP
2020
osCommerce 2.3.4.1 – ‘title’ Persistent Cross-Site Scripting
This exploit allows an attacker to inject malicious code into the title section of the osCommerce 2.3.4.1 admin panel, leading to persistent cross-site scripting.
Mitigation:
Update to a patched version of osCommerce or apply necessary security measures to prevent cross-site scripting attacks.