DOM XSS Vulnerability in SimplCommerce Product by SimplCommerce
CVE-2020-29587

5.4MEDIUM

Key Information:

Vendor
CVE Published:
14 January 2021

What is CVE-2020-29587?

SimplCommerce, specifically version 1.0.0-rc, is vulnerable to a DOM XSS flaw due to its use of the Bootbox.js library. This library facilitates the generation of dialog boxes using Bootstrap modals. However, Bootbox.js lacks sanitization mechanisms for user inputs, leading to a scenario where malicious scripts can be injected through the jQuery .html() function directly into the dialog's content. This vulnerability exposes applications to potential exploitation, allowing attackers to execute harmful scripts in the context of the affected website.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.