Cross-Site Scripting Vulnerability in Ecommerce-CodeIgniter-Bootstrap
CVE-2020-25088
6.1MEDIUM
Key Information:
- Vendor
- CVE Published:
- 3 September 2020
What is CVE-2020-25088?
The Ecommerce-CodeIgniter-Bootstrap framework prior to August 3, 2020, is susceptible to a Cross-Site Scripting (XSS) attack through the blog publishing feature. Specifically, the vulnerability exists in the file application/modules/admin/views/blog/blogpublish.php, where untrusted data may be improperly handled, allowing an attacker to execute arbitrary JavaScript in the context of the affected application, potentially leading to data theft or session hijacking. Users of this framework should ensure they have updated to a patched version to mitigate these risks.