CVE-2024-58296
MEDIUM 5.3EPSS 0.4%
CE Phoenix v3.0.1 contains a stored cross-site scripting vulnerability in the currencies administration panel that allows attackers to inject malicious scripts. Attackers can insert XSS payloads in the title field to execute arbitrary JavaScript when administrators view the currencies page.
- CVSS v4.0
- 5.3 MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS
- 0.36% chance of exploitation in the next 30 days, 29th percentile
- Published
- 2025-12-11
- Updated
- 2026-07-14
Proof-of-concept exploits (2)
- https://www.exploit-db.com/exploits/52015
- https://demos6.softaculous.com/CE_Phoenixx3r6jqi4kl/admin/currencies.php