CVE-2023-43709: Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
Published Sep 30, 2023
·Updated
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "configurationtitle1" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Affected Software
1 affected component
osCommerce oscommerce=4.12.56860
Event History
Sep 30, 2023
CVE Published
via MITRE·02:01 AM
Data Sourced
via MITRE·02:01 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-43709?
CVE-2023-43709 is a Cross-Site Scripting (XSS) vulnerability in Os Commerce 4.12.56860.
2
How does CVE-2023-43709 work?
CVE-2023-43709 allows attackers to inject malicious JavaScript code through the "configuration_title[1](MODULE)" parameter in Os Commerce.
3
What is the severity of CVE-2023-43709?
CVE-2023-43709 has a severity rating of high (5.4).
4
How does CVE-2023-43709 affect Os Commerce?
CVE-2023-43709 affects Os Commerce version 4.12.56860.
5
How can I fix CVE-2023-43709 in Os Commerce?
To fix CVE-2023-43709 in Os Commerce, you should update to a patched version of the software as soon as it becomes available.