Description
Cross-site scripting (XSS) vulnerability in zc_install/includes/modules/pages/database_setup/header_php.php in Zen Cart 1.5.0 and earlier, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the db_username parameter to zc_install/index.php.
Remediation
References
Related Vulnerabilities
Dolphin Other Vulnerability (CVE-2006-4189)
Liferay DXP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-26265)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-1454)
WordPress Plugin Import any XML or CSV File to WordPress Cross-Site Scripting (3.6.2)