CVE-2023-4406: medium-severity vulnerability in KC Group E-Commerce Software
XSS in KC Group's E-Commerce Software
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.1epss 0.5%
exploitation probability
0.5%top 57% of all CVEs
observed exploitation
nono source reports it
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KC Group E-Commerce Software allows Reflected XSS.
This issue affects E-Commerce Software: through 20231123.
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
KC Group · E-Commerce Software