CVE-2023-43717: Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "MSEARCHHIGHLIGHTENABLETITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-43717.
What is the severity rating for CVE-2023-43717?
CVE-2023-43717 has a severity rating of 5.4 (high).
How does the Cross-Site Scripting (XSS) vulnerability in Os Commerce work?
The XSS vulnerability in Os Commerce allows attackers to inject JS through the "MSEARCH_HIGHLIGHT_ENABLE_TITLE[1]" parameter, potentially leading to the execution of unauthorized scripts within a user's web browser.
What version of Os Commerce is affected by CVE-2023-43717?
Version 4.12.56860 of Os Commerce is affected by CVE-2023-43717.
How can I fix the Cross-Site Scripting (XSS) vulnerability in Os Commerce?
To fix the XSS vulnerability in Os Commerce, it is recommended to update to a patched version of the software as soon as it becomes available.