CVE-2024-26521
EUVD-2024-2378612.03.2024, 05:15
HTML Injection vulnerability in CE Phoenix v1.0.8.20 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted payload to the english.php component.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| oscommerce | ce_phoenix | 𝑥 < 1.0.8.20 | ADP |