CVE-2022-35212: XSS
Published Aug 18, 2022
·Updated
osCommerce2 before v2.3.4.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the function tepdberror().
Affected Software
1 affected component
osCommerce oscommerce<2.3.4.1
Event History
Aug 18, 2022
CVE Published
via MITRE·07:30 PM
Data Sourced
via MITRE·07:30 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this osCommerce vulnerability?
The vulnerability ID for this osCommerce vulnerability is CVE-2022-35212.
2
What type of vulnerability is CVE-2022-35212?
CVE-2022-35212 is a cross-site scripting (XSS) vulnerability.
3
Which version of osCommerce is affected by CVE-2022-35212?
osCommerce version up to and excluding 2.3.4.1 is affected by CVE-2022-35212.
4
What is the severity of CVE-2022-35212?
The severity of CVE-2022-35212 is medium, with a CVSS score of 6.1.
5
How can I fix CVE-2022-35212?
To fix CVE-2022-35212, it is recommended to update osCommerce to version 2.3.4.1 or later.