PT-2018-14747 · Oscommerce · Oscommerce
Hexifeo
·
Published
2018-11-06
·
Updated
2020-08-24
·
CVE-2018-18964
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
osCommerce version 2.3.4.1
Description
The issue is related to an incomplete '.htaccess' file for blacklist filtering in the product page. Specifically, the .htaccess file in catalog/images/ bans the html extension, but there are several extensions, such as the svg extension, in which contained HTML can be executed.
Recommendations
For osCommerce version 2.3.4.1, consider updating the .htaccess file in catalog/images/ to include additional extensions that can execute HTML, such as the svg extension, to prevent potential exploitation. As a temporary workaround, restrict access to the catalog/images/ directory to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oscommerce