oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /catalog/admin/administrators.php and /catalog/password_reset.php
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOscommerce
APPOscommerce2.3.4.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2020-27976CRITICAL9.8PL ✓same product
OS command injection w osCommerce Phoenix CE via parametr 'from' w mail.php
CVE-2019-25496HIGH8.8same product
osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate ...
CVE-2019-25495HIGH8.8same product
osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate ...
CVE-2019-25497HIGH8.8same product
osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate ...
CVE-2023-6579HIGH7.3same product
A vulnerability, which was classified as critical, has been found in osCommerce 4. Affected by this issue is s...