CVE-2023-43614: XSS
Published Sep 26, 2023
·Updated
Cross-site scripting vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
Affected Software
2 affected components
Collne Welcart E-commerce Wordpress>=2.7<=2.8.21
Welcart Welcart e-Commerce WordPress>=2.7<=2.8.21
Event History
Sep 26, 2023
CVE Published
via MITRE·08:19 AM
Data Sourced
via MITRE·08:19 AM
DescriptionWeakness
Sep 27, 2023
Data Sourced
via NVD·03:19 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-43614?
The severity of CVE-2023-43614 is medium, with a CVSS score of 6.1.
2
How does CVE-2023-43614 affect Welcart e-Commerce?
CVE-2023-43614 affects Welcart e-Commerce versions 2.7 to 2.8.21.
3
What is the vulnerability type of CVE-2023-43614?
CVE-2023-43614 is a cross-site scripting (XSS) vulnerability.
4
How can a remote attacker exploit CVE-2023-43614?
A remote unauthenticated attacker can exploit CVE-2023-43614 by injecting an arbitrary script on the Order Data Edit page of Welcart e-Commerce.
5
Are there any patches or updates available for CVE-2023-43614?
Yes, patches or updates are available. Please refer to the official Welcart e-Commerce website for more information.