{"id":"CVE-2020-29587","details":"SimplCommerce 1.0.0-rc uses the Bootbox.js library, which allows creation of programmatic dialog boxes using Bootstrap modals. The Bootbox.js library intentionally does not perform any sanitization of user input, which results in a DOM XSS, because it uses the jQuery .html() function to directly append the payload to a dialog.","modified":"2026-07-08T21:25:38.168945Z","published":"2021-01-14T16:15:18.227Z","references":[{"type":"EVIDENCE","url":"https://github.com/simplcommerce/SimplCommerce/issues/969"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/simplcommerce/simplcommerce","events":[{"introduced":"8c8444dd53f577d5eeca292daedc6ce3589e3fa0"},{"last_affected":"8c8444dd53f577d5eeca292daedc6ce3589e3fa0"}],"database_specific":{"cpe":"cpe:2.3:a:simplcommerce:simplcommerce:1.0.0:rc:*:*:*:*:*:*","extracted_events":[{"introduced":"1.0.0-rc"},{"last_affected":"1.0.0-rc"}],"source":"CPE_STRING"}}],"versions":["1.0.0-rc","v1.0.0-rc"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-29587.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}