osCommerce Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2023-43710 - Vulnerability Database

osCommerce Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2023-43710

Medium
Reference: CVE-2023-43710
Title: osCommerce Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the quotconfiguration_title1MODULE_SHIPPING_PERCENT_TEXT_TITLEquot parameter potentially leading to unauthorized execution of scripts within a user39s web browser.