Cross-Site Scripting Vulnerability in OpenCart by OpenCart
CVE-2020-29470
4.8MEDIUM
What is CVE-2020-29470?
OpenCart version 3.0.3.6 is vulnerable to Cross-Site Scripting (XSS) in the mail Subject field. This vulnerability enables attackers to inject a malicious XSS payload, which triggers when a user opens the email. Exploiting this flaw, an attacker can steal sensitive cookies and potentially compromise user sessions, posing a significant risk to website security.