The package s-cart/core before 4.4 are vulnerable to Cross-site Scripting (XSS) via the admin panel.
References
Link | Resource |
---|---|
https://snyk.io/vuln/SNYK-PHP-SCARTCORE-1047609 | Exploit Third Party Advisory |
https://github.com/s-cart/s-cart/releases/tag/v4.4 | Third Party Advisory |
https://github.com/s-cart/core/commit/f4b2811293063a3a2bb497b2512d8a18bd202219 | Patch Third Party Advisory |
https://github.com/s-cart/s-cart/issues/52 | Exploit Third Party Advisory |
Configurations
Information
Published : 2020-12-15 08:15
Updated : 2020-12-16 08:01
NVD link : CVE-2020-28456
Mitre link : CVE-2020-28456
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
s-cart
- s-cart