Description
OpenCart 3.0.3.3 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section because of a lack of entity encoding. NOTE: this issue exists because of an incomplete fix for CVE-2020-10596. The vendor states "this is not a massive issue as you are still required to be logged into the admin.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p9qw-fh38-x37f | OpenCart Cross-site Scripting |
References
| Link | Providers |
|---|---|
| https://github.com/opencart/opencart/issues/7974 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:32:14.614Z
Reserved: 2020-06-09T00:00:00.000Z
Link: CVE-2020-13980
No data.
Status : Modified
Published: 2020-06-09T14:15:10.217
Modified: 2024-11-21T05:02:17.100
Link: CVE-2020-13980
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA