PT-2025-23799 · Oscommerce · Oscommerce
Published
2025-06-04
·
Updated
2025-06-17
·
CVE-2025-40674
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
osCommerce version 4
Description
The issue is a Reflected Cross-Site Scripting (XSS) that allows an attacker to execute JavaScript code in the victim's browser. This can be achieved by sending a malicious URL using any parameter name in the "/watch/en/about-us" endpoint. The attacker can exploit this to steal sensitive user data, such as session cookies, or perform actions on behalf of the user.
Recommendations
For osCommerce version 4, update to a version that includes a fix for this issue, as using outdated versions poses a significant risk. As a temporary workaround, consider restricting access to the "/watch/en/about-us" endpoint to minimize the risk of exploitation. Avoid using parameters in this endpoint until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oscommerce