First published: Fri Mar 19 2021(Updated: )
Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_page.php or includes/templates/responsive_classic/common/tpl_main_page.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zen Cart | =1.5.6d |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6578 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting attacks.
To resolve CVE-2020-6578, update to a patched version of Zen Cart that addresses the reflected XSS vulnerability.
CVE-2020-6578 can be exploited for reflected cross-site scripting attacks, which may compromise user sessions and data.
CVE-2020-6578 specifically affects Zen Cart version 1.5.6d.
Detailed information about CVE-2020-6578 can typically be found in security advisories that address the vulnerability.