CVE-2023-43725 – Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
https://notcve.org/view.php?id=CVE-2023-43725
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "orders_products_status_name_long[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser. Os Commerce es actualmente susceptible a una vulnerabilidad de Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los atacantes inyectar JS a través del parámetro "orders_products_status_name_long[1]", lo que podría provocar la ejecución no autorizada de scripts en el navegador web de un usuario. • https://fluidattacks.com/advisories/bts https://www.oscommerce.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-43724 – Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
https://notcve.org/view.php?id=CVE-2023-43724
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "derb6zmklgtjuhh2cn5chn2qjbm2stgmfa4.oastify.comscription[1][name]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser. Os Commerce es actualmente susceptible a una vulnerabilidad de Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los atacantes inyectar JS a través del parámetro "derb6zmklgtjuhh2cn5chn2qjbm2stgmfa4.oastify.comscription[1][name]", lo que podría provocar la ejecución no autorizada de scripts en el navegador web de un usuario. • https://fluidattacks.com/advisories/bts https://www.oscommerce.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-43723 – Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
https://notcve.org/view.php?id=CVE-2023-43723
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "orders_status_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser. Os Commerce es actualmente susceptible a una vulnerabilidad de Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los atacantes inyectar JS a través del parámetro "orders_status_name[1]", lo que podría provocar la ejecución no autorizada de scripts en el navegador web de un usuario. • https://fluidattacks.com/advisories/bts https://www.oscommerce.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-43722 – Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
https://notcve.org/view.php?id=CVE-2023-43722
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "orders_status_groups_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser. Os Commerce es actualmente susceptible a una vulnerabilidad de Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los atacantes inyectar JS a través del parámetro "orders_status_groups_name[1]", lo que podría provocar la ejecución no autorizada de scripts en el navegador web de un usuario. • https://fluidattacks.com/advisories/bts https://www.oscommerce.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-43721 – Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
https://notcve.org/view.php?id=CVE-2023-43721
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "PACKING_SLIPS_SUMMARY_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser. Os Commerce es actualmente susceptible a una vulnerabilidad de Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los atacantes inyectar JS a través del parámetro "PACKING_SLIPS_SUMMARY_TITLE[1]", lo que podría provocar la ejecución no autorizada de scripts en el navegador web de un usuario. • https://fluidattacks.com/advisories/bts https://www.oscommerce.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •