First published: Tue Sep 26 2023(Updated: )
Cross-site scripting vulnerability in Item List page registration process of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Collne Welcart | >=2.7<=2.8.21 | |
Welcart Plugin | >=2.7<=2.8.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-41233.
Welcart e-Commerce versions 2.7 to 2.8.21.
The severity of CVE-2023-41233 is medium.
The vulnerability allows a remote unauthenticated attacker to inject an arbitrary script through the Item List page registration process.
Yes, updates to Welcart e-Commerce versions 2.8.22 or higher can fix this vulnerability.