ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-20640”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-20640
Published
2021-06-28
CVSS:
6.1
ShadowTrackr CVSS:
1.2
Summary:
Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.