CE Phoenix v3.0.1 contains a stored cross-site scripting vulnerability in the currencies administration panel that allows attackers to inject malicious scripts. Attackers can insert XSS payloads in the title field to execute arbitrary JavaScript when administrators view the currencies page.
CVSS
No CVSS.
References
Configurations
No configuration.
History
11 Dec 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-11 22:15
Updated : 2025-12-12 15:17
NVD link : CVE-2024-58296
Mitre link : CVE-2024-58296
CVE.ORG link : CVE-2024-58296
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
