Vulnerability Description
In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feature` parameter. The problem is fixed in 1.7.6.5
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Prestashop | Prestashop | < 1.7.6.5 |
Related Weaknesses (CWE)
References
- https://github.com/PrestaShop/PrestaShop/commit/9efca621a0b74b82dafa91e6b9551200PatchThird Party Advisory
- https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-87jh-7xpg-6v93PatchThird Party Advisory
- https://github.com/PrestaShop/PrestaShop/commit/9efca621a0b74b82dafa91e6b9551200PatchThird Party Advisory
- https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-87jh-7xpg-6v93PatchThird Party Advisory
FAQ
What is CVE-2020-5269?
CVE-2020-5269 is a vulnerability with a CVSS score of 4.1 (MEDIUM). In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feature` parameter. The problem is fixed in 1.7.6.5
How severe is CVE-2020-5269?
CVE-2020-5269 has been rated MEDIUM with a CVSS base score of 4.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5269?
Check the references section above for vendor advisories and patch information. Affected products include: Prestashop Prestashop.