The package s-cart/core before 4.4 are vulnerable to Cross-site Scripting (XSS) via the admin panel.
References
Link | Resource |
---|---|
https://github.com/s-cart/core/commit/f4b2811293063a3a2bb497b2512d8a18bd202219 | Patch Third Party Advisory |
https://github.com/s-cart/s-cart/issues/52 | Exploit Third Party Advisory |
https://github.com/s-cart/s-cart/releases/tag/v4.4 | Third Party Advisory |
https://snyk.io/vuln/SNYK-PHP-SCARTCORE-1047609 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2020-12-15 16:15
Updated : 2024-02-28 18:08
NVD link : CVE-2020-28456
Mitre link : CVE-2020-28456
CVE.ORG link : CVE-2020-28456
JSON object : View
Products Affected
s-cart
- s-cart
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')