First published: Thu Apr 16 2020(Updated: )
In the ps_link module for PrestaShop before version 3.1.0, there is a stored XSS when you create or edit a link list block with the title field. The problem is fixed in 3.1.0
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Prestashop | >=1.0.4<3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5266 is classified as a medium severity vulnerability due to its stored XSS implications.
To fix CVE-2020-5266, you need to upgrade to PrestaShop version 3.1.0 or later.
CVE-2020-5266 allows attackers to execute malicious scripts in the context of users who interact with the compromised link list block.
PrestaShop versions prior to 3.1.0 are vulnerable to CVE-2020-5266.
CVE-2020-5266 can compromise the integrity and confidentiality of your website by enabling stored XSS attacks.