Vulnerability Description
In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the contact form. The problem is fixed in 1.7.6.8
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Prestashop | Prestashop | >= 1.6.0.4, < 1.7.6.8 |
Related Weaknesses (CWE)
References
- https://github.com/PrestaShop/PrestaShop/commit/562a231fec18a928e4a601860416fe11PatchThird Party Advisory
- https://github.com/PrestaShop/PrestaShop/releases/tag/1.7.6.8Third Party Advisory
- https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-5cp2-r794-w37wThird Party Advisory
- https://github.com/PrestaShop/PrestaShop/commit/562a231fec18a928e4a601860416fe11PatchThird Party Advisory
- https://github.com/PrestaShop/PrestaShop/releases/tag/1.7.6.8Third Party Advisory
- https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-5cp2-r794-w37wThird Party Advisory
FAQ
What is CVE-2020-15161?
CVE-2020-15161 is a vulnerability with a CVSS score of 5.4 (MEDIUM). In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the contact form. The problem is fixed in 1.7.6.8
How severe is CVE-2020-15161?
CVE-2020-15161 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15161?
Check the references section above for vendor advisories and patch information. Affected products include: Prestashop Prestashop.