First published: Tue Dec 29 2020(Updated: )
OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. An admin can upload a profile image as a malicious code using JavaScript. Whenever anyone will see the profile picture, the code will execute and XSS will trigger.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/opencart/opencart | =3.0.3.6 | |
OpenCart | =3.0.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this OpenCart vulnerability is CVE-2020-29471.
CVE-2020-29471 has a severity level of medium (4.8).
CVE-2020-29471 allows an admin to upload a profile image that contains malicious JavaScript code, which can lead to cross-site scripting (XSS) attacks in OpenCart 3.0.3.6.
An admin can upload a profile image with JavaScript code that will be executed whenever someone views the profile picture, triggering the XSS vulnerability.
To mitigate the vulnerability, users should update OpenCart to a version that has addressed the XSS issue.