PT-2020-13815 · Opencart · Opencart

·

CVE-2020-13980

·

Published

2020-06-09

·

Updated

2024-08-04

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenCart version 3.0.3.3
Description The issue allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section because of a lack of entity encoding. This problem exists due to an incomplete fix for a previous issue. The vendor notes that this is not a significant issue since it requires being logged into the admin section.
Recommendations For OpenCart version 3.0.3.3, consider temporarily restricting access to the image upload section for users until a proper fix is applied to prevent XSS attacks. As a mitigation measure, ensure that all filenames are properly sanitized and entity encoded to prevent malicious input.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13980
GHSA-P9QW-FH38-X37F

Affected Products

Opencart