CVE-2009-0541 (MEDIUM) CVSS 4.3
🟡 Severity: MEDIUM (CVSS 4.3)
Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the username field in an admin/ request to index.php, possibly related to the login[username] parameter and the app/code/core/Mage/Admin/Model/Session.php login function; (2) the email address field in an admin/index/forgotpassword/ request to index.php, possibly related to the email parameter and the app/code/core/Mage/Adminhtml/controllers/IndexController.php forgotpasswordAction function; or (3) the return parameter to the default URI under downloader/.
Published: 2009-02-25
Last Modified: 2026-04-23 ⚠️
References:
- archives.neohapsis.com/archives/…
- secunia.com/advisorie…
- securitytracker.com/id
- www.securityfocus.com/bid/33872
- exchange.xforce.ibmcloud.com/vulnerabi…