First published: Tue Sep 26 2023(Updated: )
Cross-site scripting vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Collne Welcart | >=2.7<=2.8.21 | |
Welcart Plugin | >=2.7<=2.8.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-43614 is medium, with a CVSS score of 6.1.
CVE-2023-43614 affects Welcart e-Commerce versions 2.7 to 2.8.21.
CVE-2023-43614 is a cross-site scripting (XSS) vulnerability.
A remote unauthenticated attacker can exploit CVE-2023-43614 by injecting an arbitrary script on the Order Data Edit page of Welcart e-Commerce.
Yes, patches or updates are available. Please refer to the official Welcart e-Commerce website for more information.