Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

M0R3Try

#44016of 53,624
6.1Total CVSS
Vulnerabilities · 1
PT-2021-10999
6.1
2021-05-18
Tinyshop · Tinyshop · CVE-2020-24026
Name of the Vulnerable Software and Affected Versions: TinyShop version 1.2.0 Description: The issue is related to a stored XSS vulnerability. It can be exploited via the `explain first` and `again explain` parameters of the "/evaluate/index.php" page, potentially resulting in cross-site scripting (XSS) or information disclosure. The vulnerability may be exploited remotely. Recommendations: For TinyShop version 1.2.0, as a temporary workaround, consider restricting access to the "/evaluate/index.php" page or disabling the use of the `explain first` and `again explain` parameters until a fix is available. Avoid using these parameters in the affected page to minimize the risk of exploitation.