Description
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /catalog/admin/administrators.php and /catalog/password_reset.php
Remediation
References
Related Vulnerabilities
Moodle CVE-2021-36402 Vulnerability (CVE-2021-36402)
Joomla! Core 3.x.x Information Disclosure (3.0.0 - 3.8.7)
WordPress Plugin Media from FTP Cross-Site Scripting (9.89)
SharePoint CVE-2024-21426 Vulnerability (CVE-2024-21426)
WordPress Plugin Gallery-Video Gallery and Youtube Gallery Cross-Site Scripting (1.2.4)