MEDIUM6.1
GHSA-wxxx-2x6v-979f
Reflected XSS in Zen Cart before 1.5.7a
Quick fix
GHSA-wxxx-2x6v-979f — zencart/zencart: upgrade to the fixed version with the command below.
composer require zencart/zencart:^1.5.7aDetails
Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to `includes/templates/template_default/common/tpl_main_page.php` or `includes/templates/responsive_classic/common/tpl_main_page.php.`
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/zencart/zencart
Introduced in:
0Fixed in: 1.5.7aFix
composer require zencart/zencart:^1.5.7a