CVE-2012-1413: Zen-Cart Zen Cart
Low severity, CVSS 2.6. EPSS: 0.8% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in zc_install/includes/modules/pages/database_setup/header_php.php in Zen Cart 1.5.0 and earlier, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the db_username parameter to zc_install/index.php.
Affected products
- Zen-Cart Zen Cart: any version; up to and including 1.5; version 1.1.0 only; version 1.1.3 only; version 1.2.0d only; version 1.2.1 only; …
Published 2012-05-27. Last modified 2026-06-16.