CVE-2020-10596 is a stored Cross-Site Scripting (XSS) vulnerability affecting OpenCart version 3.0.3.2, allowing authenticated attackers to inject malicious scripts through crafted filenames in the image upload section. Rated Medium severity (CVSS 5.4), it requires user interaction and authenticated access, potentially leading to limited impact on confidentiality and integrity. While not actively exploited in the wild and lacking Metasploit or Nuclei modules, an ExploitDB proof-of-concept exists, though it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.3.2CPE matchmatch criteria | cpe:2.3:a:opencart:opencart:3.0.3.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.