CVE-2020-23360: Critical severity oscommerce poll booth vulnerability
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /catalog/admin/administrators.php and /catalog/passwordreset.php
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-23360?
CVE-2020-23360 is a vulnerability in osCommerce v2.3.4.1 that allows a non-identical password to bypass checks in user registration and password rechecking.
How severe is CVE-2020-23360?
CVE-2020-23360 has a severity rating of 9.8, which is considered critical.
What is the affected software of CVE-2020-23360?
osCommerce v2.3.4.1 is the affected software of CVE-2020-23360.
How can the vulnerability be exploited?
The vulnerability can be exploited by registering with a non-identical password or during password reset in osCommerce v2.3.4.1.
Are there any references for CVE-2020-23360?
Yes, you can find more information about CVE-2020-23360 at the following link: [https://github.com/osCommerce/oscommerce2/issues/658]