Cross-Site Scripting Vulnerability in OpenCart by OpenCart
CVE-2020-13980
4.8MEDIUM
Summary
OpenCart version 3.0.3.3 is susceptible to a Cross-Site Scripting (XSS) vulnerability that allows remote authenticated users to exploit the system by uploading a crafted filename through the user image upload section. This vulnerability arises due to insufficient entity encoding, which can lead to potential security risks if exploited. It’s important to note that this flaw is tied to an incomplete resolution of a previous issue (CVE-2020-10596). While the attacker must be logged into the admin panel, it highlights the significance of maintaining secure coding practices and timely software updates to safeguard against such vulnerabilities.
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved