Vulnerability Description
In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/default/template/header.tpl, and themes/new-theme/js/header.js.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Prestashop | Prestashop | 1.7.6.2 |
Related Weaknesses (CWE)
References
- https://github.com/PrestaShop/PrestaShop/pull/17050/commitsPatchThird Party Advisory
- https://github.com/PrestaShop/PrestaShop/pull/17050/commitsPatchThird Party Advisory
FAQ
What is CVE-2020-6632?
CVE-2020-6632 is a vulnerability with a CVSS score of 6.1 (MEDIUM). In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/default/template/header.tpl, and themes/new-theme/js/...
How severe is CVE-2020-6632?
CVE-2020-6632 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6632?
Check the references section above for vendor advisories and patch information. Affected products include: Prestashop Prestashop.