Description
HTML Injection vulnerability in CE Phoenix v1.0.8.20 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted payload to the english.php component.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 27 Feb 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oscommerce
Oscommerce ce Phoenix |
|
| CPEs | cpe:2.3:a:oscommerce:ce_phoenix:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oscommerce
Oscommerce ce Phoenix |
|
| Metrics |
ssvc
|
Tue, 27 Aug 2024 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-27T20:13:50.048Z
Reserved: 2024-02-19T00:00:00.000Z
Link: CVE-2024-26521
Updated: 2024-08-02T00:07:19.779Z
Status : Deferred
Published: 2024-03-12T05:15:47.653
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-26521
No data.
OpenCVE Enrichment
No data.
Weaknesses