First published: Thu Apr 16 2020(Updated: )
In PrestaShop module ps_linklist versions before 3.1.0, there is a stored XSS when using custom URLs. The problem is fixed in version 3.1.0
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Prestashop Linklist | >=3.0.0<3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5273 has a medium severity due to the potential for stored cross-site scripting (XSS) attacks.
To fix CVE-2020-5273, upgrade the PrestaShop ps_linklist module to version 3.1.0 or later.
The vulnerability in CVE-2020-5273 is caused by improper handling of custom URLs allowing stored XSS.
CVE-2020-5273 affects all versions of the ps_linklist module prior to 3.1.0.
There is no known workaround for CVE-2020-5273; upgrading to the patched version is strongly recommended.