CVE-2018-20703: XSS
Published Jan 13, 2019
·Updated
CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string.
Affected Software
1 affected component
Cubecart CubeCart=6.2.2
Event History
Jan 13, 2019
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-20703?
CVE-2018-20703 is a vulnerability in CubeCart 6.2.2 that allows for Reflected XSS via a /{ADMIN-FILE}/ query string.
2
How severe is CVE-2018-20703?
CVE-2018-20703 has a severity rating of medium with a CVSS score of 5.4.
3
How does CVE-2018-20703 affect CubeCart?
CVE-2018-20703 affects CubeCart version 6.2.2 by enabling Reflected XSS through a /{ADMIN-FILE}/ query string.
4
What is the Common Weakness Enumeration (CWE) for CVE-2018-20703?
The Common Weakness Enumeration (CWE) for CVE-2018-20703 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
5
How can I fix CVE-2018-20703?
To fix CVE-2018-20703, it is recommended to update CubeCart to a version that has patched the vulnerability.