First published: Tue Apr 30 2024(Updated: )
A vulnerability, which was classified as problematic, was found in osCommerce 4. Affected is an unknown function of the file /catalog/all-products. The manipulation of the argument cat leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-262488. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
osCommerce Poll Booth | =4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4348 is classified as problematic due to its potential for exploitation via cross-site scripting.
To fix CVE-2024-4348, update osCommerce to the latest version and sanitize input parameters to prevent cross-site scripting.
CVE-2024-4348 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject scripts.
CVE-2024-4348 affects osCommerce version 4.
Yes, CVE-2024-4348 can be exploited remotely by manipulating the cat argument.