CVE-2023-43713

Publication date

2023-09-30 20:53:29

Family

Fluid Attacks

State

PUBLISHED

Description

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability, which allows attackers to inject JS via the "title" parameter, in the "/admin/admin-menu/add-submit" endpoint, which can lead to unauthorized execution of scripts in a users web browser.