Cross-Site Scripting Vulnerability in Ecommerce-CodeIgniter-Bootstrap by Kiril Kirkov
CVE-2020-25089
6.1MEDIUM
Key Information:
- Vendor
- CVE Published:
- 3 September 2020
What is CVE-2020-25089?
The Ecommerce-CodeIgniter-Bootstrap framework, prior to the update on August 3, 2020, is prone to a Cross-Site Scripting (XSS) vulnerability through the 'discounts.php' view file located in the admin module. This flaw allows attackers to inject malicious scripts into web pages viewed by users, potentially compromising user data and application integrity. It is crucial for developers using this framework to apply the latest patches to mitigate this security risk.