CVE-2020-13980: XSS
Published Jun 9, 2020
·Updated
DISPUTED OpenCart 3.0.3.3 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section because of a lack of entity encoding. NOTE: this issue exists because of an incomplete fix for CVE-2020-10596. The vendor states "this is not a massive issue as you are still required to be logged into the admin."
Affected Software
2 affected components
composer/opencart/opencart<=3.0.3.3
OpenCart opencart=3.0.3.3
Event History
Jun 9, 2020
CVE Published
via MITRE·01:44 PM
Data Sourced
via MITRE·01:44 PM
Description
Disputed
02:15 PM
May 24, 2022
Advisory Published
via GitHub·05:19 PM
Frequently Asked Questions
1
What is the vulnerability ID for this OpenCart version?
The vulnerability ID for OpenCart version 3.0.3.3 is CVE-2020-13980.
2
What is the severity of CVE-2020-13980?
CVE-2020-13980 has a severity rating of medium.
3
What is the affected software version of CVE-2020-13980?
The affected software version of CVE-2020-13980 is OpenCart 3.0.3.3.
4
What is the CWE number associated with CVE-2020-13980?
The CWE number associated with CVE-2020-13980 is CWE-79.
5
Is there a fix available for CVE-2020-13980?
There is currently no fix available for CVE-2020-13980.