CVE-2023-43713: Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability, which allows attackers to inject JS via the "title" parameter, in the "/admin/admin-menu/add-submit" endpoint, which can lead to unauthorized execution of scripts in a user's web browser.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Os Commerce vulnerability?
The vulnerability ID for this Os Commerce vulnerability is CVE-2023-43713.
What is the severity of CVE-2023-43713?
The severity of CVE-2023-43713 is high with a severity value of 5.4.
Which software version is affected by CVE-2023-43713?
The software version affected by CVE-2023-43713 is Oscommerce 4.12.56860.
What is the impact of CVE-2023-43713?
CVE-2023-43713 allows attackers to inject JS via the 'title' parameter, leading to unauthorized execution of scripts in a user's web browser.
Where can I find more information about CVE-2023-43713?
You can find more information about CVE-2023-43713 at the following references: [https://fluidattacks.com/advisories/bts/](https://fluidattacks.com/advisories/bts/) and [https://www.oscommerce.com/](https://www.oscommerce.com/).