CVE-2020-12058

MEDIUM

osCommerce CE Phoenix < 1.0.6.0 - Cross-Site Scripting via Multiple Admin Page Parameters

Title source: llm
STIX 2.1

Description

Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php, catalog/admin/languages.php, catalog/admin/countries.php, catalog/admin/tax_classes.php, catalog/admin/reviews.php, or catalog/admin/zones.php; or the zpage or spage parameter to catalog/admin/geo_zones.php.

References (3)

Core 3

Scores

CVSS v3 6.1
EPSS 0.0095
EPSS Percentile 56.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
oscommerce/ce_phoenix 1.0.6.0
Published Sep 03, 2020
Tracked Since Feb 18, 2026