CVE-2020-5273: Stored XSS with custom URLs in PrestaShop module ps_linklist
Published Apr 16, 2020
·Updated
In PrestaShop module pslinklist versions before 3.1.0, there is a stored XSS when using custom URLs. The problem is fixed in version 3.1.0
Affected Software
1 affected component
Prestashop Prestashop Linklist Prestashop>=3.0.0<3.1.0
Remediation
Event History
Apr 16, 2020
CVE Published
via MITRE·09:15 PM
Data Sourced
via MITRE·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-5273?
CVE-2020-5273 has a medium severity due to the potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2020-5273?
To fix CVE-2020-5273, upgrade the PrestaShop ps_linklist module to version 3.1.0 or later.
3
What causes the vulnerability in CVE-2020-5273?
The vulnerability in CVE-2020-5273 is caused by improper handling of custom URLs allowing stored XSS.
4
Which versions of ps_linklist are affected by CVE-2020-5273?
CVE-2020-5273 affects all versions of the ps_linklist module prior to 3.1.0.
5
Is there a workaround for CVE-2020-5273 if I can't upgrade immediately?
There is no known workaround for CVE-2020-5273; upgrading to the patched version is strongly recommended.