Security Advisory

CVE-2023-4406

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-11-23 09:37:09
Last updated 2026-05-21 12:38:27
Assigner TR-CERT
CVSS score 6.1
State PUBLISHED

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KC Group E-Commerce Software allows Reflected XSS. This issue affects E-Commerce Software: through 20231123.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.