VYPR

Ce Phoenix

by OsCommerce

CVEs (1)

  • CVE-2020-12058MedSep 3, 2020
    risk 0.00cvss 6.1epss 0.01

    Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php,…