CVE-2020-12058: XSS
Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/orderstatus.php, catalog/admin/taxrates.php, catalog/admin/languages.php, catalog/admin/countries.php, catalog/admin/taxclasses.php, catalog/admin/reviews.php, or catalog/admin/zones.php; or the zpage or spage parameter to catalog/admin/geozones.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this osCommerce CE Phoenix vulnerability?
The vulnerability ID for this osCommerce CE Phoenix vulnerability is CVE-2020-12058.
What is the severity of CVE-2020-12058?
The severity of CVE-2020-12058 is medium with a score of 6.1.
How can an attacker exploit CVE-2020-12058?
An attacker can exploit CVE-2020-12058 by injecting and executing arbitrary JavaScript code through several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0.
Which versions of osCommerce CE Phoenix are affected by CVE-2020-12058?
Versions before 1.0.6.0 of osCommerce CE Phoenix are affected by CVE-2020-12058.
How can I fix CVE-2020-12058?
To fix CVE-2020-12058, it is recommended to upgrade osCommerce CE Phoenix to version 1.0.6.0 or later.