Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_page.php or includes/templates/responsive_classic/common/tpl_main_page.php.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| zencart/zencart(Packagist) | 0 | 1.5.7a | N/A |
CVSS Metrics