Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.
References
Link | Resource |
---|---|
https://www.jianshu.com/p/219755c047a1 | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-06-28T17:29:08
Updated: 2021-06-28T17:29:08
Reserved: 2020-08-13T00:00:00
Link: CVE-2020-20640
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-06-28T18:15:07.937
Modified: 2021-07-01T18:34:42.420
Link: CVE-2020-20640
JSON object: View
Redhat Information
No data.
CWE