CVE-2020-6578: Cross-site Scripting
(updated )
Zen Cart d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_page.php
or includes/templates/responsive_classic/common/tpl_main_page.php
.
References
Detect and mitigate CVE-2020-6578 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →