CVE-2011-4567

Cross-site scripting (XSS) vulnerability in includes/templates/template_default/templates/tpl_gv_send_default.php in Zen Cart before 1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a gv_send action to index.php, a different vulnerability than CVE-2011-4547.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
VendorProductVersion
zen-cartzen_cart
𝑥
≤ 1.3.9
zen-cartzen_cart
1.1.0
zen-cartzen_cart
1.1.3
zen-cartzen_cart
1.2.0d:d
zen-cartzen_cart
1.2.1:patch1
zen-cartzen_cart
1.2.1d:d
zen-cartzen_cart
1.2.2d:d
zen-cartzen_cart
1.2.3d:d
zen-cartzen_cart
1.2.4.1
zen-cartzen_cart
1.2.4d:d
zen-cartzen_cart
1.2.5d:d
zen-cartzen_cart
1.2.6d:d
zen-cartzen_cart
1.3
zen-cartzen_cart
1.3.0.2
zen-cartzen_cart
1.3.2
zen-cartzen_cart
1.3.5
zen-cartzen_cart
1.3.6
zen-cartzen_cart
1.3.7
zen-cartzen_cart
1.3.8
zen-cartzen_cart
1.3.8a:a
𝑥
= Vulnerable software versions