CVE-2020-10596: XSS
OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10596?
The severity of CVE-2020-10596 is medium with a CVSS score of 5.4.
How does CVE-2020-10596 impact OpenCart 3.0.3.2?
CVE-2020-10596 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section in OpenCart 3.0.3.2.
How can an attacker exploit CVE-2020-10596?
An attacker can exploit CVE-2020-10596 by uploading an image with a crafted filename that contains malicious code, which will be executed when the image is viewed by another user.
Is there a fix available for CVE-2020-10596?
Yes, a fix for CVE-2020-10596 is available. It is recommended to update to a patched version of OpenCart.
Where can I find more information about CVE-2020-10596?
You can find more information about CVE-2020-10596 on the NIST NVD website, OpenCart GitHub issue tracker, and Packet Storm Security.