First published: Tue Dec 29 2020(Updated: )
OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Subject field of mail. This vulnerability can allow an attacker to inject the XSS payload in the Subject field of the mail and each time any user will open that mail of the website, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/opencart/opencart | =3.0.3.6 | |
OpenCart | =3.0.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-29470 is a cross-site scripting (XSS) vulnerability in OpenCart 3.0.3.6 that allows an attacker to inject malicious code in the Subject field of mail.
CVE-2020-29470 allows an attacker to inject XSS payload in the Subject field of mail, which is triggered when any user opens the mail on the website.
CVE-2020-29470 has a severity rating of 4.8, which is considered medium.
OpenCart 3.0.3.6 is affected by CVE-2020-29470.
An attacker can exploit CVE-2020-29470 by injecting a malicious XSS payload in the mail Subject field and tricking users into opening the email on the website.