VYPR
Unrated severityNVD Advisory· Published May 8, 2020· Updated Aug 4, 2024

Potential remote code execution in Shopizer

CVE-2020-11006

Description

In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed when information is fetched from backend. This has been patched in version 2.11.0.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.