First published: Wed Nov 25 2020(Updated: )
osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of newsletters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oscommerce Oscommerce | =2.3.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-29070 is medium.
The affected software for CVE-2020-29070 is osCommerce 2.3.4.1.
CVE-2020-29070 exploits osCommerce 2.3.4.1 by allowing an authenticated user to enter an XSS payload into the title section of newsletters.
To mitigate CVE-2020-29070, it is recommended to update osCommerce to a version that addresses the XSS vulnerability.
You can find more information about CVE-2020-29070 in the following references: [link1](https://forums.oscommerce.com/forum/17-news-and-announcements/), [link2](https://github.com/aslanemre/cve-2020-29070/blob/main/CVE-2020-29070), [link3](https://github.com/gburton/CE-Phoenix/commits/master).