ZeroHour

CVE-2020-23447

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p50
Published
()
Modified
Description

newbee-mall 1.0 is affected by cross-site scripting in shop-cart/settle. Users only need to write xss payload in their address information when buying goods, which is triggered when viewing the "View Recipient Information" of this order in "Order Management Office".

Vendors
newbee-mall project
Products
newbee-mall
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.