CVE-2020-23447

MEDIUM

newbee-mall 1.0 - Stored Cross-Site Scripting in Order Management Office

Title source: llm
STIX 2.1

Description

newbee-mall 1.0 is affected by cross-site scripting in shop-cart/settle. Users only need to write xss payload in their address information when buying goods, which is triggered when viewing the "View Recipient Information" of this order in "Order Management Office".

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/newbee-ltd/newbee-mall/issues/33

Scores

CVSS v3 6.1
EPSS 0.0024
EPSS Percentile 47.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
newbee-mall_project/newbee-mall 1.0
Published Jan 26, 2021
Tracked Since Feb 18, 2026