Opencart Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-10596 - Vulnerability Database

Opencart Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-10596

Medium
Reference: CVE-2020-10596
Title: Opencart Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users39 image upload section.