Lucene search

K
cvePatchstackCVE-2023-47839
HistoryNov 23, 2023 - 12:15 a.m.

CVE-2023-47839

2023-11-2300:15:09
CWE-79
Patchstack
web.nvd.nist.gov
72
cve-2023-47839
cross-site scripting
implecode ecommerce
product catalog
wordpress
security vulnerability
nvd

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

EPSS

0

Percentile

14.0%

Improper Neutralization of Input During Web Page Generation (β€˜Cross-site Scripting’) vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress plugin <=Β 3.3.26 versions.

Affected configurations

Nvd
Vulners
Node
implecodeecommerce_product_catalogRange≀3.3.26wordpress
VendorProductVersionCPE
implecodeecommerce_product_catalog*cpe:2.3:a:implecode:ecommerce_product_catalog:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "ecommerce-product-catalog",
    "product": "eCommerce Product Catalog Plugin for WordPress",
    "vendor": "impleCode",
    "versions": [
      {
        "changes": [
          {
            "at": "3.3.27",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "3.3.26",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

EPSS

0

Percentile

14.0%

Related for CVE-2023-47839