CVE-2020-6578: XSS
Published Mar 19, 2021
·Updated
Zen Cart 1.5.6d allows reflected XSS via the mainpage parameter to includes/templates/templatedefault/common/tplmainpage.php or includes/templates/responsiveclassic/common/tplmainpage.php.
Affected Software
1 affected component
Zen-cart Zen Cart=1.5.6d
Event History
Mar 19, 2021
CVE Published
via MITRE·03:29 AM
Data Sourced
via MITRE·03:29 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-6578?
CVE-2020-6578 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2020-6578?
To resolve CVE-2020-6578, update to a patched version of Zen Cart that addresses the reflected XSS vulnerability.
3
What types of attacks can CVE-2020-6578 be exploited for?
CVE-2020-6578 can be exploited for reflected cross-site scripting attacks, which may compromise user sessions and data.
4
Which versions of Zen Cart are affected by CVE-2020-6578?
CVE-2020-6578 specifically affects Zen Cart version 1.5.6d.
5
Where can I find more information about CVE-2020-6578?
Detailed information about CVE-2020-6578 can typically be found in security advisories that address the vulnerability.