Lanh Le

2 exploits Active since Dec 2020
CVE-2020-28456 WRITEUP HIGH WRITEUP
S-cart < 4.4 - XSS
The package s-cart/core before 4.4 are vulnerable to Cross-site Scripting (XSS) via the admin panel.
CVSS 7.3
CVE-2020-28457 WRITEUP HIGH WRITEUP
S-cart < 4.4 - XSS
This affects the package s-cart/core before 4.4. The search functionality of the admin dashboard in core/src/Admin/Controllers/AdminOrderController.phpindex is vulnerable to XSS.
CVSS 7.2