newbee-mall 1.0 is affected by cross-site scripting in shop-cart/settle. Users only need to write xss payload in their address information when buying goods, which is triggered when viewing the "View Recipient Information" of this order in "Order Management Office".
References
Link | Resource |
---|---|
https://github.com/newbee-ltd/newbee-mall/issues/33 | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-01-26T17:15:11
Updated: 2021-01-26T17:15:11
Reserved: 2020-08-13T00:00:00
Link: CVE-2020-23447
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-01-26T18:15:42.660
Modified: 2021-01-30T01:31:45.157
Link: CVE-2020-23447
JSON object: View
Redhat Information
No data.
CWE