First published: Fri Mar 19 2021(Updated: )
Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_page.php or includes/templates/responsive_classic/common/tpl_main_page.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zen-cart Zen Cart | =1.5.6d |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.