CVE-2023-43702: Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "trackingnumber" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-43702?
The severity of CVE-2023-43702 is high.
What is the affected software of CVE-2023-43702?
The affected software of CVE-2023-43702 is OsCommerce version 4.12.56860.
How does CVE-2023-43702 affect OsCommerce?
CVE-2023-43702 allows attackers to inject JS through the "tracking_number" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Are there any references related to CVE-2023-43702?
Yes, you can find references related to CVE-2023-43702 at the following links: [Fluid Attacks](https://fluidattacks.com/advisories/bts/) and [OsCommerce](https://www.oscommerce.com/).
What is the Common Weakness Enumeration (CWE) of CVE-2023-43702?
The Common Weakness Enumeration (CWE) of CVE-2023-43702 is 79.