CVE-2020-29475

MEDIUM

nopCommerce Store 4.30 - XSS

Title source: llm
STIX 2.1

Description

nopCommerce Store 4.30 is affected by cross-site scripting (XSS) in the Schedule tasks name field. This vulnerability can allow an attacker to inject the XSS payload in Schedule tasks and each time any user will go to that page of the website, the XSS triggers and attacker can able to steal the cookie according to the crafted payload.

Exploits (1)

exploitdb WORKING POC
by Hemant Patidar · textwebappsmultiple
https://www.exploit-db.com/exploits/49093

Scores

CVSS v3 4.8
EPSS 0.0049
EPSS Percentile 65.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
nopcommerce/store 4.30
Published Dec 29, 2020
Tracked Since Feb 18, 2026