Cross-Site Scripting Vulnerability in Ecommerce-CodeIgniter-Bootstrap
CVE-2020-25088
Key Information:
- Vendor
- CVE Published:
- 3 September 2020
What is CVE-2020-25088?
The Ecommerce-CodeIgniter-Bootstrap framework prior to August 3, 2020, is susceptible to a Cross-Site Scripting (XSS) attack through the blog publishing feature. Specifically, the vulnerability exists in the file application/modules/admin/views/blog/blogpublish.php, where untrusted data may be improperly handled, allowing an attacker to execute arbitrary JavaScript in the context of the affected application, potentially leading to data theft or session hijacking. Users of this framework should ensure they have updated to a patched version to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
