First published: Tue Jun 09 2020(Updated: )
** DISPUTED ** OpenCart 3.0.3.3 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section because of a lack of entity encoding. NOTE: this issue exists because of an incomplete fix for CVE-2020-10596. The vendor states "this is not a massive issue as you are still required to be logged into the admin."
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/opencart/opencart | <=3.0.3.3 | |
OpenCart | =3.0.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for OpenCart version 3.0.3.3 is CVE-2020-13980.
CVE-2020-13980 has a severity rating of medium.
The affected software version of CVE-2020-13980 is OpenCart 3.0.3.3.
The CWE number associated with CVE-2020-13980 is CWE-79.
There is currently no fix available for CVE-2020-13980.