First published: Sun Nov 26 2023(Updated: )
A vulnerability was found in osCommerce 4. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /catalog/compare of the component Instant Message Handler. The manipulation of the argument compare with the input 40dz4iq"><script>alert(1)</script>zohkx leads to cross site scripting. The attack may be launched remotely. VDB-246122 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6296 is a vulnerability found in osCommerce 4 that allows for cross-site scripting (XSS).
CVE-2023-6296 has a severity rating of medium (6.1).
osCommerce 4.0 is affected by CVE-2023-6296.
CVE-2023-6296 impacts the Instant Message Handler component by allowing for cross-site scripting (XSS) through manipulation of the compare argument.
To fix CVE-2023-6296 in osCommerce 4.0, it is recommended to apply the latest security patches and updates provided by osCommerce.