First published: Wed Jan 27 2021(Updated: )
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /catalog/admin/administrators.php and /catalog/password_reset.php
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oscommerce Oscommerce | =2.3.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23360 is a vulnerability in osCommerce v2.3.4.1 that allows a non-identical password to bypass checks in user registration and password rechecking.
CVE-2020-23360 has a severity rating of 9.8, which is considered critical.
osCommerce v2.3.4.1 is the affected software of CVE-2020-23360.
The vulnerability can be exploited by registering with a non-identical password or during password reset in osCommerce v2.3.4.1.
Yes, you can find more information about CVE-2020-23360 at the following link: [https://github.com/osCommerce/oscommerce2/issues/658]