CE Phoenix v3.0.1 contains a stored cross-site scripting vulnerability in the currencies administration panel that allows attackers to inject malicious scripts. Attackers can insert XSS payloads in the title field to execute arbitrary JavaScript when administrators view the currencies page.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 17 Dec 2025 07:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Dec 2025 18:00:00 +0900

Type Values Removed Values Added
First Time appeared Phoenixcart
Phoenixcart ce Phoenix Cart
Vendors & Products Phoenixcart
Phoenixcart ce Phoenix Cart

Fri, 12 Dec 2025 06:45:00 +0900

Type Values Removed Values Added
Description CE Phoenix v3.0.1 contains a stored cross-site scripting vulnerability in the currencies administration panel that allows attackers to inject malicious scripts. Attackers can insert XSS payloads in the title field to execute arbitrary JavaScript when administrators view the currencies page.
Title CE Phoenix v3.0.1 Stored Cross-Site Scripting via admin/currencies.php
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-16T16:31:28.553Z

Reserved: 2025-12-11T00:58:28.456Z

Link: CVE-2024-58296

cve-icon Vulnrichment

Updated: 2025-12-16T16:28:11.921Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-11T22:15:50.740

Modified: 2025-12-12T15:17:31.973

Link: CVE-2024-58296

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-12T17:49:43Z

Weaknesses