VDB
Sign up
MEDIUM6.1

GHSA-wxxx-2x6v-979f

Reflected XSS in Zen Cart before 1.5.7a

Quick fix

GHSA-wxxx-2x6v-979f — zencart/zencart: upgrade to the fixed version with the command below.

composer require zencart/zencart:^1.5.7a

Details

Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to `includes/templates/template_default/common/tpl_main_page.php` or `includes/templates/responsive_classic/common/tpl_main_page.php.`

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/zencart/zencart
Introduced in: 0Fixed in: 1.5.7a
Fixcomposer require zencart/zencart:^1.5.7a

References