CVE-2020-15161: Potential XSS in PrestaShop
Published Sep 24, 2020
·Updated
In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the contact form. The problem is fixed in 1.7.6.8
Affected Software
1 affected component
Prestashop PrestaShop>=1.6.0.4<1.7.6.8
Remediation
Event History
Sep 24, 2020
CVE Published
via MITRE·10:10 PM
Data Sourced
via MITRE·10:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-15161?
CVE-2020-15161 is a vulnerability in PrestaShop prior to version 1.7.6.8 that allows an attacker to inject JavaScript through the contact form.
2
How severe is CVE-2020-15161?
CVE-2020-15161 has a severity rating of 6.1, which is considered medium.
3
How can the CVE-2020-15161 vulnerability be fixed?
The CVE-2020-15161 vulnerability can be fixed by updating PrestaShop to version 1.7.6.8 or later.
4
What is the Common Weakness Enumeration (CWE) associated with CVE-2020-15161?
CVE-2020-15161 is associated with CWE-79, which is the Cross-Site Scripting (XSS) vulnerability.
5
Where can I find more information about CVE-2020-15161?
You can find more information about CVE-2020-15161 on the PrestaShop GitHub page and the associated security advisories.