CVE-2024-35362: XSS
Published May 22, 2024
·Updated
Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via ecshop/articlecat.php.
Affected Software
2 affected components
ECShop EcShop
shopex ecshop=3.6
Event History
May 22, 2024
CVE Published
via MITRE·03:44 PM
Data Sourced
via MITRE·03:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35362?
The severity of CVE-2024-35362 is classified as medium due to its potential impact on user data through Cross Site Scripting (XSS).
2
How do I fix CVE-2024-35362?
To fix CVE-2024-35362, update your Ecshop instance to the latest version where this vulnerability is patched.
3
Which versions of Ecshop are affected by CVE-2024-35362?
CVE-2024-35362 affects Ecshop version 3.6 and possibly earlier versions.
4
What kind of attack does CVE-2024-35362 enable?
CVE-2024-35362 enables Cross Site Scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages.
5
Where can I find more information about CVE-2024-35362?
More information about CVE-2024-35362 can typically be found in the official Ecshop security advisories or forums.