vendor:
OpenCart
by:
Kailash Bohara
5.4
CVSS
MEDIUM
Stored Cross Site Scripting
79
CWE
Product Name: OpenCart
Affected Version From: OpenCart < 3.0.3.2
Affected Version To: OpenCart < 3.0.3.2
Patch Exists: YES
Related CWE: CVE-2020-10596
CPE: a:opencart:opencart
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2020
OpenCart 3.0.3.2 – Stored Cross Site Scripting (Authenticated)
OpenCart versions prior to 3.0.3.2 are vulnerable to a stored cross-site scripting vulnerability. An authenticated attacker can exploit this vulnerability by uploading a malicious image file containing an XSS payload to the Image Manager section. This payload will be executed each time someone visits the Image Manager section.
Mitigation:
Upgrade to OpenCart version 3.0.3.2 or later.