Reflected Cross-Site Scripting (XSS) in osCommerce v4. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the name of any parameter in /watch/en/about-us. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-18487 Reflected Cross-Site Scripting (XSS) in osCommerce v4. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the name of any parameter in /watch/en/about-us. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
Fixes

Solution

There is no reported solution at this time.


Workaround

No workaround given by the vendor.

History

Tue, 17 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Jun 2025 09:00:00 +0000

Type Values Removed Values Added
Description Reflected Cross-Site Scripting (XSS) in osCommerce v4. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the name of any parameter in /watch/en/about-us. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
Title Reflected Cross-Site Scripting (XSS) in osCommerce
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-06-17T14:31:48.511Z

Reserved: 2025-04-16T08:38:14.999Z

Link: CVE-2025-40674

cve-icon Vulnrichment

Updated: 2025-06-17T14:31:39.814Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-17T09:15:23.650

Modified: 2025-06-17T20:50:23.507

Link: CVE-2025-40674

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-06-20T13:55:53Z