Cross-Site Scripting Vulnerability in Ecommerce-CodeIgniter-Bootstrap by Kiril Kirkov
CVE-2020-25089

6.1MEDIUM

What is CVE-2020-25089?

The Ecommerce-CodeIgniter-Bootstrap framework, prior to the update on August 3, 2020, is prone to a Cross-Site Scripting (XSS) vulnerability through the 'discounts.php' view file located in the admin module. This flaw allows attackers to inject malicious scripts into web pages viewed by users, potentially compromising user data and application integrity. It is crucial for developers using this framework to apply the latest patches to mitigate this security risk.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.