CVE-2017-8833: XSS
Published May 8, 2017
·Updated
Zen Cart 1.6.0 has XSS in the mainpage parameter to index.php. NOTE: 1.6.0 is not an official release but the vendor's README.md file offers a link to v160.zip with a description of "Download latest in-development version from github."
Affected Software
1 affected component
Zen-cart Zen Cart=1.6.0
Event History
May 8, 2017
CVE Published
via MITRE·06:10 AM
Data Sourced
via MITRE·06:10 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8833?
CVE-2017-8833 has a medium severity level due to its potential for XSS attacks via the main_page parameter.
2
How do I fix CVE-2017-8833?
To fix CVE-2017-8833, upgrade to the latest stable version of Zen Cart that addresses this vulnerability.
3
What effect does CVE-2017-8833 have on Zen Cart 1.6.0?
CVE-2017-8833 allows attackers to execute arbitrary JavaScript code, potentially compromising user data.
4
Is Zen Cart 1.6.0 an official release regarding CVE-2017-8833?
No, Zen Cart 1.6.0 is not an official release and is labeled as an in-development version.
5
What parameters are affected by CVE-2017-8833?
CVE-2017-8833 specifically targets the main_page parameter in index.php.