PT-2025-23799 · Oscommerce · Oscommerce

CVE-2025-40674

·

Published

2025-06-04

·

Updated

2025-06-17

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions osCommerce version 4
Description The issue is a Reflected Cross-Site Scripting (XSS) that allows an attacker to execute JavaScript code in the victim's browser. This can be achieved by sending a malicious URL using any parameter name in the "/watch/en/about-us" endpoint. The attacker can exploit this to steal sensitive user data, such as session cookies, or perform actions on behalf of the user.
Recommendations For osCommerce version 4, update to a version that includes a fix for this issue, as using outdated versions poses a significant risk. As a temporary workaround, consider restricting access to the "/watch/en/about-us" endpoint to minimize the risk of exploitation. Avoid using parameters in this endpoint until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-40674

Affected Products

Oscommerce