CVE-2018-1000640
Summary
| CVE | CVE-2018-1000640 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-20 19:31:00 UTC |
| Updated | 2018-10-19 17:21:00 UTC |
| Description | OpenCart-Overclocked version <=1.11.1 contains a Cross Site Scripting (XSS) vulnerability in User input entered unsanitised within JS function in the template that can result in Unauthorised actions and access to data, stealing session information, denial of service. This attack appear to be exploitable via Malicious input passed in GET parameter. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Villagedefrance | Opencart-overclocked | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| OpenCart-Overclocked Reflected XSS | 0dd - The Zero (0) Day Division | MISC | 0dd.zone | Third Party Advisory |
| Reflected XSS in OpenBay Template · Issue #190 · villagedefrance/OpenCart-Overclocked · GitHub | CONFIRM | github.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.