First published: Wed Oct 28 2020(Updated: )
osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oscommerce Oscommerce | <1.0.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-27975.
The severity level of CVE-2020-27975 is high.
The vulnerability in osCommerce Phoenix CE before 1.0.5.4 allows Cross-Site Request Forgery (CSRF) attacks on the admin/define_language.php page.
To fix this vulnerability, update osCommerce Phoenix CE to version 1.0.5.4 or higher.
You can find more information about this vulnerability at the following link: https://herolab.usd.de/security-advisories/usd-2020-0027/