First published: Tue Sep 26 2023(Updated: )
Cross-site scripting vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Collne Welcart | >=2.7<=2.8.21 | |
Welcart Plugin | >=2.7<=2.8.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-43484 is a cross-site scripting vulnerability in the Item List page of Welcart e-Commerce versions 2.7 to 2.8.21.
CVE-2023-43484 has a severity keyword of medium and a severity value of 6.1.
An attacker can exploit CVE-2023-43484 by injecting an arbitrary script through the Item List page of affected Welcart e-Commerce versions.
CVE-2023-43484 affects Welcart e-Commerce versions 2.7 to 2.8.21.
Yes, a fix is available. Please refer to the reference links for more information.