Medium severity4.8NVD Advisory· Published Nov 25, 2020· Updated Jun 17, 2026
CVE-2020-29070
CVE-2020-29070
Description
osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of newsletters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3=2.3.4.1+ 2 more
- (no CPE)range: =2.3.4.1
- (no CPE)
- cpe:2.3:a:oscommerce:oscommerce:2.3.4.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- github.com/gburton/CE-Phoenix/commits/masternvdPatchThird Party Advisory
- github.com/aslanemre/cve-2020-29070/blob/main/CVE-2020-29070nvdExploitThird Party Advisory
- forums.oscommerce.com/forum/17-news-and-announcements/nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.