Opencart Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-10596 - Vulnerability Database
Opencart Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-10596
Medium
Reference:
CVE-2020-10596
Title:
Opencart Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users39 image upload section.