osCommerce Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2023-43713 - Vulnerability Database

osCommerce Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2023-43713

Medium
Reference: CVE-2023-43713
Title: osCommerce Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability which allows attackers to inject JS via the quottitlequot parameter in the quot/admin/admin-menu/add-submitquot endpoint which can lead to unauthorized execution of scripts in a user39s web browser.