CVE-2023-41233: XSS
Published Sep 26, 2023
·Updated
Cross-site scripting vulnerability in Item List page registration process of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
Affected Software
2 affected components
Collne Welcart E-commerce Wordpress>=2.7<=2.8.21
Welcart Welcart e-Commerce WordPress>=2.7<=2.8.21
Event History
Sep 26, 2023
CVE Published
via MITRE·08:15 AM
Data Sourced
via MITRE·08:15 AM
DescriptionWeakness
Sep 27, 2023
Data Sourced
via NVD·03:19 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2023-41233.
2
What software is affected by this vulnerability?
Welcart e-Commerce versions 2.7 to 2.8.21.
3
What is the severity of CVE-2023-41233?
The severity of CVE-2023-41233 is medium.
4
How does CVE-2023-41233 work?
The vulnerability allows a remote unauthenticated attacker to inject an arbitrary script through the Item List page registration process.
5
Are there any known fixes for CVE-2023-41233?
Yes, updates to Welcart e-Commerce versions 2.8.22 or higher can fix this vulnerability.