CVE-2020-26225: Reflected XSS in PrestaShop Product Comments
In PrestaShop Product Comments before version 4.2.0, an attacker could inject malicious web code into the users' web browsers by creating a malicious link. The problem was introduced in version 4.0.0 and is fixed in 4.2.0
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-26225?
CVE-2020-26225 is a vulnerability in PrestaShop Product Comments before version 4.2.0 where an attacker could inject malicious web code into users' web browsers via a malicious link.
How can an attacker exploit CVE-2020-26225?
An attacker can exploit CVE-2020-26225 by creating a malicious link that injects malicious web code into users' web browsers.
Which versions of PrestaShop Product Comments are affected by CVE-2020-26225?
Versions of PrestaShop Product Comments before version 4.2.0 are affected by CVE-2020-26225.
How can I fix CVE-2020-26225?
To fix CVE-2020-26225, upgrade to version 4.2.0 of PrestaShop Product Comments.
What is the severity of CVE-2020-26225?
CVE-2020-26225 has a severity rating of 6.1 (high).