CVE-2025-40674: Reflected Cross-Site Scripting (XSS) in osCommerce
Reflected Cross-Site Scripting (XSS) in osCommerce v4. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the name of any parameter in /watch/en/about-us. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40674?
CVE-2025-40674 is considered a high-severity vulnerability due to the potential for an attacker to execute JavaScript code in the victim's browser.
How do I fix CVE-2025-40674?
To fix CVE-2025-40674, update to the latest version of osCommerce that contains the security patch addressing this vulnerability.
Who is affected by CVE-2025-40674?
Users of osCommerce v4 are affected by CVE-2025-40674, specifically those using the /watch/en/about-us parameter.
What type of vulnerability is CVE-2025-40674?
CVE-2025-40674 is classified as a reflected cross-site scripting (XSS) vulnerability.
Can CVE-2025-40674 lead to data theft?
Yes, CVE-2025-40674 can potentially be exploited to steal sensitive data from victims through malicious JavaScript execution.