CVE-2018-20849 Arastta eCommerce 1.6.2 is vulnerable to XSS via the PATH_INFO to the login/ URI. Source: NIST CVE-2018-20849 June 30, 2019 by admin Uncategorized