First published: Mon Jun 28 2021(Updated: )
Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Shopex Ecshop | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-20640.
CVE-2020-20640 has a severity rating of 6.1 (Medium).
The XSS vulnerability in ECShop 4.0 occurs due to security filtering issues in the user.php file.
The security policy of the safety.php file can be bypassed by using HTML entity encoding.
The XSS vulnerability in ECShop 4.0 can allow an attacker to execute arbitrary scripts in the victim's browser, potentially leading to session hijacking, defacement, or data theft.