PoC Index

CVE-2020-20640

MEDIUM 6.1EPSS 0.9%

Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.

CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
0.88% chance of exploitation in the next 30 days, 56th percentile
Published
2021-06-28
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related