CVE-2023-43484: XSS
Published Sep 26, 2023
·Updated
Cross-site scripting vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
Affected Software
2 affected components
Collne Welcart E-commerce Wordpress>=2.7<=2.8.21
Welcart Welcart e-Commerce WordPress>=2.7<=2.8.21
Event History
Sep 26, 2023
CVE Published
via MITRE·08:17 AM
Data Sourced
via MITRE·08:17 AM
DescriptionWeakness
Sep 27, 2023
Data Sourced
via NVD·03:19 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-43484?
CVE-2023-43484 is a cross-site scripting vulnerability in the Item List page of Welcart e-Commerce versions 2.7 to 2.8.21.
2
How severe is CVE-2023-43484?
CVE-2023-43484 has a severity keyword of medium and a severity value of 6.1.
3
How can an attacker exploit CVE-2023-43484?
An attacker can exploit CVE-2023-43484 by injecting an arbitrary script through the Item List page of affected Welcart e-Commerce versions.
4
Which software versions are affected by CVE-2023-43484?
CVE-2023-43484 affects Welcart e-Commerce versions 2.7 to 2.8.21.
5
Is there a fix for CVE-2023-43484?
Yes, a fix is available. Please refer to the reference links for more information.