CVE-2020-12058
Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code.
Does this matter?
Lower severity and a low EPSS score (0.96%). Track it; it rarely justifies an emergency change on its own.
Description
Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php, catalog/admin/languages.php, catalog/admin/countries.php, catalog/admin/tax_classes.php, catalog/admin/reviews.php, or catalog/admin/zones.php; or the zpage or spage parameter to catalog/admin/geo_zones.php.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.96% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- oscommerce/ce phoenix
- Source
- cve@mitre.org
References
- https://github.com/gburton/CE-Phoenix/commit/8d0fb97810bc28880415a3a31607f473bfc5fec8Patch, Third Party Advisory
- https://sisl.lab.uic.edu/projects/chess/cross-site-scripting-in-cephoenix/Third Party Advisory
- https://www.oscommerce.com/Us&News=155Vendor Advisory
- https://github.com/gburton/CE-Phoenix/commit/8d0fb97810bc28880415a3a31607f473bfc5fec8Patch, Third Party Advisory
- https://sisl.lab.uic.edu/projects/chess/cross-site-scripting-in-cephoenix/Third Party Advisory
- https://www.oscommerce.com/Us&News=155Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.