Medium severity4.8NVD Advisory· Published Dec 29, 2020· Updated Jun 17, 2026
CVE-2020-29471
CVE-2020-29471
Description
OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. An admin can upload a profile image as a malicious code using JavaScript. Whenever anyone will see the profile picture, the code will execute and XSS will trigger.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- OpenCart/OpenCartdescription
- ghsa-coords
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/49098nvdExploitThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-7vrp-3pff-c3j4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-29471ghsaADVISORY
News mentions
0No linked articles in our index yet.