CVE-2020-20508
EUVD-2020-1329524.09.2021, 22:15
Shopkit v2.7 contains a reflective cross-site scripting (XSS) vulnerability in the /account/register component, which allows attackers to hijack user credentials via a crafted payload in the E-Mail text field.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| shopkit_project | shopkit | 2.7 |
𝑥
= Vulnerable software versions