PT-2023-18817 · Unknown · Ecommerce-Codeigniter-Bootstrap

Enferaso

·

Published

2023-01-20

·

Updated

2023-01-28

·

CVE-2023-23010

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ecommerce-CodeIgniter-Bootstrap versions prior to commit d5904379ca55014c5df34c67deda982c73dc7fe5
Description The issue allows attackers to execute arbitrary code via the languages and trans load parameters in the file add product.php. This is a Cross Site Scripting (XSS) issue.
Recommendations For versions prior to commit d5904379ca55014c5df34c67deda982c73dc7fe5, consider restricting access to the add product.php file until a patch is available. As a temporary workaround, avoid using the languages and trans load parameters in the affected file until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-23010

Affected Products

Ecommerce-Codeigniter-Bootstrap