CVE-2020-5266: Stored XSS on back office edit page
Published Apr 16, 2020
·Updated
In the pslink module for PrestaShop before version 3.1.0, there is a stored XSS when you create or edit a link list block with the title field. The problem is fixed in 3.1.0
Affected Software
1 affected component
Prestashop Prestashop Link Prestashop>=1.0.4<3.1.0
Remediation
Event History
Apr 16, 2020
CVE Published
via MITRE·09:15 PM
Data Sourced
via MITRE·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-5266?
CVE-2020-5266 is classified as a medium severity vulnerability due to its stored XSS implications.
2
How do I fix CVE-2020-5266?
To fix CVE-2020-5266, you need to upgrade to PrestaShop version 3.1.0 or later.
3
What types of attacks are possible with CVE-2020-5266?
CVE-2020-5266 allows attackers to execute malicious scripts in the context of users who interact with the compromised link list block.
4
Which versions of PrestaShop are affected by CVE-2020-5266?
PrestaShop versions prior to 3.1.0 are vulnerable to CVE-2020-5266.
5
How does CVE-2020-5266 affect the security of my website?
CVE-2020-5266 can compromise the integrity and confidentiality of your website by enabling stored XSS attacks.