Cross-Site Scripting Vulnerability in Ecommerce-CodeIgniter-Bootstrap
CVE-2020-25088

6.1MEDIUM

What is CVE-2020-25088?

The Ecommerce-CodeIgniter-Bootstrap framework prior to August 3, 2020, is susceptible to a Cross-Site Scripting (XSS) attack through the blog publishing feature. Specifically, the vulnerability exists in the file application/modules/admin/views/blog/blogpublish.php, where untrusted data may be improperly handled, allowing an attacker to execute arbitrary JavaScript in the context of the affected application, potentially leading to data theft or session hijacking. Users of this framework should ensure they have updated to a patched version to mitigate these risks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.