newbee-mall 1.0 is affected by cross-site scripting in shop-cart/settle. Users only need to write xss payload in their address information when buying goods, which is triggered when viewing the "View Recipient Information" of this order in "Order Management Office".
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/newbee-ltd/newbee-mall/issues/33 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-01-26T17:15:11
Updated: 2024-08-04T14:58:15.113Z
Reserved: 2020-08-13T00:00:00
Link: CVE-2020-23447
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-01-26T18:15:42.660
Modified: 2024-11-21T05:13:48.580
Link: CVE-2020-23447
Redhat
No data.