CVE-2020-15178: Potential XSS in PrestaShop contactform
Published Sep 15, 2020
·Updated
In PrestaShop contactform module (prestashop/contactform) before version 4.3.0, an attacker is able to inject JavaScript while using the contact form. The message field was incorrectly unescaped, possibly allowing attackers to execute arbitrary JavaScript in a victim's browser.
Affected Software
1 affected component
Prestashop Contactform Prestashop<4.3.0
Remediation
Event History
Sep 15, 2020
CVE Published
via MITRE·05:50 PM
Data Sourced
via MITRE·05:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this PrestaShop contactform module vulnerability?
The vulnerability ID for this PrestaShop contactform module vulnerability is CVE-2020-15178.
2
What is the severity score of CVE-2020-15178?
CVE-2020-15178 has a severity score of 9.3 (Critical).
3
How does this vulnerability in PrestaShop contactform module work?
This vulnerability allows an attacker to inject JavaScript through the contact form by exploiting the incorrectly unescaped 'message' field.
4
What is the affected software version for this vulnerability?
The affected software version is PrestaShop contactform module before version 4.3.0.
5
How can I fix CVE-2020-15178 in PrestaShop contactform module?
To fix CVE-2020-15178, update to version 4.3.0 or above of the PrestaShop contactform module.