Medium severity6.1NVD Advisory· Published Sep 24, 2021· Updated Jun 17, 2026
CVE-2020-20508
CVE-2020-20508
Description
Shopkit v2.7 contains a reflective cross-site scripting (XSS) vulnerability in the /account/register component, which allows attackers to hijack user credentials via a crafted payload in the E-Mail text field.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Shopkit/Shopkitdescription
- cpe:2.3:a:shopkit_project:shopkit:2.7:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/samnabi/shopkit/issues/223nvdExploitIssue TrackingPatchThird Party Advisory
News mentions
0No linked articles in our index yet.