Description osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF. Remediation References CVE-2020-27975 Related Vulnerabilities WordPress Plugin Facebook Like Box Cross-Site Request Forgery (2.8.2) WordPress Plugin Email Subscribers by Icegram Express-Email Marketing, Newsletters, Automation for WordPress & WooCommerce Cross-Site Scripting (5.7.11) WordPress Plugin Visual Form Builder Unspecified Vulnerability (3.0.5) WordPress Plugin Wordfence Security-Firewall & Malware Scan Cross-Site Scripting (5.1.2) Opencart Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-13980) Severity High Classification CVE-2020-27975 CWE-352 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities