CVE-2023-43722: Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ordersstatusgroupsname[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-43722.
What is the severity of CVE-2023-43722?
The severity of CVE-2023-43722 is high with a CVSS score of 5.4.
What is the affected software?
The affected software is Os Commerce version 4.12.56860.
What is the impact of this vulnerability?
This vulnerability allows attackers to inject malicious JavaScript code, potentially leading to unauthorized execution of scripts within a user's web browser.
Are there any references for additional information?
Yes, you can find additional information at the following references: [Fluid Attacks Advisory](https://fluidattacks.com/advisories/bts/) and [Os Commerce Website](https://www.oscommerce.com/).