First published: Sun Jan 13 2019(Updated: )
CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cubecart Cubecart | =6.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20703 is a vulnerability in CubeCart 6.2.2 that allows for Reflected XSS via a /{ADMIN-FILE}/ query string.
CVE-2018-20703 has a severity rating of medium with a CVSS score of 5.4.
CVE-2018-20703 affects CubeCart version 6.2.2 by enabling Reflected XSS through a /{ADMIN-FILE}/ query string.
The Common Weakness Enumeration (CWE) for CVE-2018-20703 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
To fix CVE-2018-20703, it is recommended to update CubeCart to a version that has patched the vulnerability.