CVE-2012-1413: Zen-Cart Zen Cart

Low severity, CVSS 2.6. EPSS: 0.8% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in zc_install/includes/modules/pages/database_setup/header_php.php in Zen Cart 1.5.0 and earlier, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the db_username parameter to zc_install/index.php.

Affected products

  • Zen-Cart Zen Cart: any version; up to and including 1.5; version 1.1.0 only; version 1.1.3 only; version 1.2.0d only; version 1.2.1 only; …

Published 2012-05-27. Last modified 2026-06-16.