CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.1. See the original NVD description below for full technical details.
CVE
CVE-2023-4406
Severity
MEDIUM
CVSS
6.1
EPSS
0.53%
Original NVD Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KC Group E-Commerce Software allows Reflected XSS. This issue affects E-Commerce Software: through 20231123. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.