CVE-2023-3857: phpscriptpoint Ecommerce product.php cross site scripting
A vulnerability, which was classified as problematic, was found in phpscriptpoint Ecommerce 1.15. This affects an unknown part of the file /product.php. The manipulation of the argument id leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-235209 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3857?
The severity of CVE-2023-3857 is medium with a score of 6.1.
What is the affected software of CVE-2023-3857?
The affected software of CVE-2023-3857 is phpscriptpoint Ecommerce version 1.15.
What is the CWE ID of CVE-2023-3857?
The CWE ID of CVE-2023-3857 is 79.
How can I exploit CVE-2023-3857?
Exploiting CVE-2023-3857 requires remote attack initiation by manipulating the 'id' argument in the file /product.php, leading to cross-site scripting (XSS).
How can I fix CVE-2023-3857?
To fix CVE-2023-3857, update phpscriptpoint Ecommerce to a version that addresses the cross-site scripting vulnerability.