osCommerce Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-29070 - Vulnerability Database
osCommerce Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-29070
Medium
Reference:
CVE-2020-29070
Title:
osCommerce Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of newsletters.