CVE-2020-12058: Oscommerce CE Phoenix
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php, catalog/admin/languages.php, catalog/admin/countries.php, catalog/admin/tax_classes.php, catalog/admin/reviews.php, or catalog/admin/zones.php; or the zpage or spage parameter to catalog/admin/geo_zones.php.
Affected products
- Oscommerce CE Phoenix: version 1.0.6.0 only
Published 2020-09-03. Last modified 2026-06-17.