CVE-2020-5277: Reflected XSS with url_name parameter of PrestaShop module ps_facetedsearch
Published Mar 25, 2020
·Updated
PrestaShop module psfacetedsearch versions before 3.5.0 has a reflected XSS with urlname parameter. The problem is fixed in 3.5.0
Affected Software
1 affected component
Prestashop Faceted Search Module>1.0.0<3.5.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PrestaShop module ps_facetedsearchto a version that resolves this vulnerability.Fixed in 3.5.0
Event History
Mar 25, 2020
CVE Published
via MITRE·06:30 PM
Data Sourced
via MITRE·06:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-5277?
CVE-2020-5277 is classified as a medium severity vulnerability due to its reflected XSS nature.
2
How do I fix CVE-2020-5277?
To fix CVE-2020-5277, update the PrestaShop ps_facetedsearch module to version 3.5.0 or later.
3
Which versions of ps_facetedsearch are affected by CVE-2020-5277?
CVE-2020-5277 affects all versions of the ps_facetedsearch module before 3.5.0.
4
What type of vulnerability is CVE-2020-5277?
CVE-2020-5277 is a reflected Cross-Site Scripting (XSS) vulnerability.
5
Who is impacted by CVE-2020-5277?
Users of the PrestaShop platform using affected versions of the ps_facetedsearch module are impacted by CVE-2020-5277.