S4E just found a low dns any record query
medium·Product Based Web Vulnerabilities·Updated May 18, 2024

CVE-2024-4348 Scanner

CVE-2024-4348 scanner - Cross-Site Scripting (XSS) vulnerability in osCommerce

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-4348
4.3
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

A vulnerability, which was classified as problematic, was found in osCommerce 4. Affected is an unknown function of the file /catalog/all-products. The manipulation of the argument cat leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-262488. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
osCommerceby n/a
4
oscommerceby oscommerce
4
Updated Aug 22, 2026View on NVD →
Detail

osCommerce is a widely-used open-source e-commerce platform that allows users to create and manage online stores. It is utilized by small to medium-sized businesses for its comprehensive features and flexibility. The platform supports a range of plugins and customization options to enhance functionality. Developed by a community of developers, it is continuously updated to address security and performance issues. osCommerce is popular for its ease of use and extensive community support.

The Cross-Site Scripting (XSS) vulnerability in osCommerce v4.0 allows attackers to inject malicious scripts into web pages viewed by other users. This can be exploited remotely without authentication. The vulnerability affects the /catalog/all-products endpoint by manipulating the 'cat' parameter. Successful exploitation can result in the execution of arbitrary scripts in the context of the user's browser.

The vulnerability is found in the /catalog/all-products endpoint of osCommerce v4.0. By manipulating the 'cat' parameter, attackers can inject JavaScript code that gets executed when the page is viewed. This occurs due to insufficient input validation and escaping of user-supplied data. The specific payload used to trigger this vulnerability involves embedding a script tag within the parameter value. This leads to the execution of the injected script in the context of the victim's browser session.

Exploiting this vulnerability can lead to several harmful effects, including the theft of user session cookies, enabling the attacker to hijack sessions. It can also be used to deface web pages, redirect users to malicious sites, and perform other malicious actions. Additionally, sensitive information displayed on the affected web pages can be exposed to the attacker. Persistent exploitation can degrade user trust and damage the reputation of the affected e-commerce site.

By using the S4E platform, you can proactively identify and mitigate vulnerabilities like the Cross-Site Scripting (XSS) in your web applications. Our comprehensive scanning services provide detailed reports and actionable recommendations to enhance your security posture. Stay ahead of potential threats with continuous monitoring and expert insights. Join our platform to ensure your digital assets are secure and maintain the trust of your users. Protect your business from cyber threats with our robust Cyber Threat Exposure Management services.

References:

Solution Advice
  • Validate and sanitize all user inputs to prevent the injection of malicious scripts.
  • Implement output encoding to escape any dynamic content before rendering it in the browser.
  • Use Content Security Policy (CSP) to restrict the execution of untrusted scripts.
  • Regularly update and patch your software to incorporate the latest security fixes.
  • Conduct regular security assessments to identify and address vulnerabilities promptly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-4348 scanner - Cross-Site Scripting (XSS) vulnerability in osCommerce S4E