PT-2025-23799 · Oscommerce · Oscommerce

Published

2025-06-04

·

Updated

2025-06-17

·

CVE-2025-40674

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions osCommerce version 4
Description The issue is a Reflected Cross-Site Scripting (XSS) that allows an attacker to execute JavaScript code in the victim's browser. This can be achieved by sending a malicious URL using any parameter name in the "/watch/en/about-us" endpoint. The attacker can exploit this to steal sensitive user data, such as session cookies, or perform actions on behalf of the user.
Recommendations For osCommerce version 4, update to a version that includes a fix for this issue, as using outdated versions poses a significant risk. As a temporary workaround, consider restricting access to the "/watch/en/about-us" endpoint to minimize the risk of exploitation. Avoid using parameters in this endpoint until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-40674

Affected Products

Oscommerce