Cross-Site Scripting Vulnerability in OpenCart by OpenCart
CVE-2020-13980
4.8MEDIUM
What is CVE-2020-13980?
OpenCart version 3.0.3.3 is susceptible to a Cross-Site Scripting (XSS) vulnerability that allows remote authenticated users to exploit the system by uploading a crafted filename through the user image upload section. This vulnerability arises due to insufficient entity encoding, which can lead to potential security risks if exploited. It’s important to note that this flaw is tied to an incomplete resolution of a previous issue (CVE-2020-10596). While the attacker must be logged into the admin panel, it highlights the significance of maintaining secure coding practices and timely software updates to safeguard against such vulnerabilities.