ZeroHour

CVE-2020-18475

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p38
Published
()
Modified
Description

Cross Site Scripting (XSS) vulnerabilty exists in Hucart CMS 5.7.4 is via the mes_title field. The first user inserts a malicious script into the header field of the outbox and sends it to other users. When other users open the email, the malicious code will be executed.

Vendors
hucart
Products
hucart
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.