Description
In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed when information is fetched from backend. This has been patched in version 2.11.0.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-3399 | In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed when information is fetched from backend. This has been patched in version 2.11.0. |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T11:21:14.355Z
Reserved: 2020-03-30T00:00:00.000Z
Link: CVE-2020-11006
No data.
Status : Modified
Published: 2020-05-08T19:15:12.863
Modified: 2024-11-21T04:56:33.980
Link: CVE-2020-11006
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD