ZeroHour

CVE-2020-20640

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p57
Published
()
Modified
Description

Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.

Vendors
shopex
Products
ecshop
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.