Description
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /catalog/admin/administrators.php and /catalog/password_reset.php
Remediation
References
Related Vulnerabilities
Squid NULL Pointer Dereference Vulnerability (CVE-2018-1000027)
Atlassian Jira Incorrect Authorization Vulnerability (CVE-2019-8446)
WordPress Plugin WP CSS 'wp-css-compress.php' Local File Disclosure (2.0.5)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-28333)
WordPress Plugin ClinicalWP Core Cross-Site Scripting (1.0.5)