Lucene search

K
cvelistMitreCVELIST:CVE-2020-20640
HistoryJun 28, 2021 - 5:29 p.m.

CVE-2020-20640

2021-06-2817:29:08
mitre
www.cve.org
3
ecshop 4.0
cross site scripting
security filtering issues
user.php
html entity encoding
safety.php
xss vulnerability

EPSS

0.001

Percentile

35.1%

Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.

EPSS

0.001

Percentile

35.1%

Related for CVELIST:CVE-2020-20640