In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed when information is fetched from backend. This has been patched in version 2.11.0.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2020-05-08T18:45:12

Updated: 2020-05-08T18:45:12

Reserved: 2020-03-30T00:00:00


Link: CVE-2020-11006

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-05-08T19:15:12.863

Modified: 2020-05-13T14:13:37.683


Link: CVE-2020-11006

JSON object: View

cve-icon Redhat Information

No data.

CWE