CVE-2020-29475
Summary
| CVE | CVE-2020-29475 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-29 15:15:00 UTC |
| Updated | 2020-12-30 16:42:00 UTC |
| Description | nopCommerce Store 4.30 is affected by cross-site scripting (XSS) in the Schedule tasks name field. This vulnerability can allow an attacker to inject the XSS payload in Schedule tasks and each time any user will go to that page of the website, the XSS triggers and attacker can able to steal the cookie according to the crafted payload. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nopcommerce | Store | 4.30 | All | All | All |
| Application | Nopcommerce | Store | 4.30 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| nopCommerce Store 4.30 - 'name' Stored Cross-Site Scripting - Multiple webapps Exploit | MISC | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.