CVE-2011-4567: XSS
Cross-site scripting (XSS) vulnerability in includes/templates/templatedefault/templates/tplgvsenddefault.php in Zen Cart before 1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a gvsend action to index.php, a different vulnerability than CVE-2011-4547.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4567?
CVE-2011-4567 is considered a medium severity vulnerability due to its potential for unauthorized script injection.
How do I fix CVE-2011-4567?
To fix CVE-2011-4567, upgrade Zen Cart to version 1.5 or higher where the vulnerability is patched.
What versions of Zen Cart are affected by CVE-2011-4567?
CVE-2011-4567 affects Zen Cart versions prior to 1.5, including 1.3.8a, 1.3.2, 1.3.0.2, and others.
What type of vulnerability is CVE-2011-4567?
CVE-2011-4567 is a Cross-site Scripting (XSS) vulnerability.
Can CVE-2011-4567 be exploited remotely?
Yes, CVE-2011-4567 can be exploited remotely, allowing attackers to inject arbitrary web scripts.