Cross-Site Scripting Vulnerability in OpenCart by OpenCart
CVE-2020-13980

4.8MEDIUM

Key Information:

Vendor
Opencart
Status
Vendor
CVE Published:
9 June 2020

Summary

OpenCart version 3.0.3.3 is susceptible to a Cross-Site Scripting (XSS) vulnerability that allows remote authenticated users to exploit the system by uploading a crafted filename through the user image upload section. This vulnerability arises due to insufficient entity encoding, which can lead to potential security risks if exploited. It’s important to note that this flaw is tied to an incomplete resolution of a previous issue (CVE-2020-10596). While the attacker must be logged into the admin panel, it highlights the significance of maintaining secure coding practices and timely software updates to safeguard against such vulnerabilities.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-13980 : Cross-Site Scripting Vulnerability in OpenCart by OpenCart | SecurityVulnerability.io