Required CVE Record Information
Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "admin_firstname" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
CWE 1 Total
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
5.4 | MEDIUM | 3.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
References 2 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- https://fluidattacks.com/advisories/bts/ x_transferred
- https://www.oscommerce.com/ x_transferred