First published: Thu Sep 03 2020(Updated: )
Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php, catalog/admin/languages.php, catalog/admin/countries.php, catalog/admin/tax_classes.php, catalog/admin/reviews.php, or catalog/admin/zones.php; or the zpage or spage parameter to catalog/admin/geo_zones.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
osCommerce CE Phoenix | =1.0.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this osCommerce CE Phoenix vulnerability is CVE-2020-12058.
The severity of CVE-2020-12058 is medium with a score of 6.1.
An attacker can exploit CVE-2020-12058 by injecting and executing arbitrary JavaScript code through several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0.
Versions before 1.0.6.0 of osCommerce CE Phoenix are affected by CVE-2020-12058.
To fix CVE-2020-12058, it is recommended to upgrade osCommerce CE Phoenix to version 1.0.6.0 or later.