PT-2023-18648 · Collne · Welcart E-Commerce

Le Ngoc Anh

·

Published

2023-03-29

·

Updated

2023-04-06

·

CVE-2023-22705

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Collne Inc. Welcart e-Commerce plugin versions prior to 2.8.11
Description The issue is related to an Unauth. Reflected Cross-Site Scripting (XSS) vulnerability. This vulnerability allows for reflected cross-site scripting attacks without authentication.
Recommendations For versions prior to 2.8.11, update to version 2.8.11 or later to resolve the issue. At the moment, there is no other information about additional mitigation measures for this vulnerability.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-22705

Affected Products

Welcart E-Commerce