CE Phoenix v3.0.1 Stored Cross-Site Scripting via admin/currencies.php
Vulnerability Description
CE Phoenix v3.0.1 contains a stored cross-site scripting vulnerability in the currencies administration panel that allows attackers to inject malicious scripts. Attackers can insert XSS payloads in the title field to execute arbitrary JavaScript when administrators view the currencies page.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-58296
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- tmrswrr
References
- https://www.exploit-db.com/exploits/52015
- https://phoenixcart.org/
- https://demos6.softaculous.com/CE_Phoenixx3r6jqi4kl/admin/currencies.php
- https://www.softaculous.com/apps/ecommerce/CE_Phoenix
- https://www.vulncheck.com/advisories/ce-phoenix-v-stored-cross-site-scripting-via-currencies-administration
Affected Vendor
PhoenixCart
View all reports →