This affects the package s-cart/core before 4.4. The search functionality of the admin dashboard in core/src/Admin/Controllers/AdminOrderController.phpindex is vulnerable to XSS.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-28457.json"
[ { "events": [ { "introduced": "0" }, { "fixed": "4.4" } ] }, { "events": [ { "introduced": "0" }, { "fixed": "4.4" } ] } ]