Medium severity6.1NVD Advisory· Published Jan 26, 2021· Updated Jun 17, 2026
CVE-2020-23447
CVE-2020-23447
Description
newbee-mall 1.0 is affected by cross-site scripting in shop-cart/settle. Users only need to write xss payload in their address information when buying goods, which is triggered when viewing the "View Recipient Information" of this order in "Order Management Office".
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:newbee-mall_project:newbee-mall:1.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:newbee-mall_project:newbee-mall:1.0:*:*:*:*:*:*:*
- (no CPE)range: =1.0
- newbee-mall/newbee-malldescription
Patches
Vulnerability mechanics
References
1- github.com/newbee-ltd/newbee-mall/issues/33nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.