Cross-Site Scripting Vulnerability in Ecommerce CodeIgniter Bootstrap
CVE-2020-25087

6.1MEDIUM

What is CVE-2020-25087?

The Ecommerce-CodeIgniter-Bootstrap framework, prior to the August 3, 2020 update, is susceptible to a Cross-Site Scripting (XSS) vulnerability in the advanced settings language management module. This flaw can potentially allow an attacker to inject malicious scripts, compromising the integrity and security of user sessions and data. Proper validation and sanitization of inputs in application/modules/admin/views/advanced_settings/languages.php are essential to mitigate these risks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.