CVE-2023-43729: Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "xselltypename[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Os Commerce vulnerability?
The vulnerability ID for the Os Commerce vulnerability is CVE-2023-43729.
What is the severity of CVE-2023-43729?
The severity of CVE-2023-43729 is high, with a CVSS score of 5.4.
How does the Os Commerce XSS vulnerability work?
The Os Commerce XSS vulnerability allows attackers to inject JavaScript through the "xsell_type_name[1]" parameter, potentially leading to unauthorized execution of scripts in a user's web browser.
Which version of Os Commerce is affected by CVE-2023-43729?
Os Commerce version 4.12.56860 is affected by CVE-2023-43729.
Where can I find more information about the Os Commerce vulnerability?
You can find more information about the Os Commerce vulnerability on the following websites: [Fluid Attacks](https://fluidattacks.com/advisories/bts/) and [Os Commerce](https://www.oscommerce.com/).