peter bassill · operator
$ cve CVE-2020-29470 JSON

CVE-2020-29470 EXPLOIT

4.8
MEDIUM · CVSS 3.1 · EPSS 1.7% (pctl 77)

Patch early

A public exploit exists.

Description

OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Subject field of mail. This vulnerability can allow an attacker to inject the XSS payload in the Subject field of the mail and each time any user will open that mail of the website, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.

Scoring

CVSS4.8 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS1.71% — more likely to be exploited than 77% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2020-12-29
Last modified2026-06-17

Affected (1)

VendorProduct
opencartopencart

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD