CVE-2023-43715: Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ENTRYFIRSTNAMEMINLENGTHTITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Os Commerce vulnerability?
The vulnerability ID of this Os Commerce vulnerability is CVE-2023-43715.
What is the severity of CVE-2023-43715?
The severity of CVE-2023-43715 is high with a score of 5.4.
How does the CVE-2023-43715 vulnerability affect Os Commerce?
The CVE-2023-43715 vulnerability in Os Commerce allows attackers to inject JS through the "ENTRY_FIRST_NAME_MIN_LENGTH_TITLE[1]" parameter, potentially leading to unauthorized script execution in a user's web browser.
Is there a fix available for CVE-2023-43715?
Yes, a fix is available for CVE-2023-43715. It is recommended to apply the latest security patch provided by Os Commerce to mitigate this vulnerability.
Where can I find more information about this vulnerability in Os Commerce?
You can find more information about this vulnerability in Os Commerce on the following websites: [Fluid Attacks Advisory](https://fluidattacks.com/advisories/bts/) and [Os Commerce Official Website](https://www.oscommerce.com/).