CVE-2020-6632: XSS
Published Jan 9, 2020
·Updated
In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/default/template/header.tpl, and themes/new-theme/js/header.js.
Affected Software
1 affected component
Prestashop PrestaShop=1.7.6.2
Event History
Jan 9, 2020
CVE Published
via MITRE·01:23 AM
Data Sourced
via MITRE·01:23 AM
Description
Data Sourced
via NVD·02:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this PrestaShop vulnerability?
The vulnerability ID for this PrestaShop vulnerability is CVE-2020-6632.
2
What is the severity of CVE-2020-6632?
The severity of CVE-2020-6632 is medium.
3
How does the XSS vulnerability in PrestaShop 1.7.6.2 occur?
The XSS vulnerability in PrestaShop 1.7.6.2 occurs during the addition or removal of a QuickAccess link.
4
Which files are related to the XSS vulnerability in PrestaShop 1.7.6.2?
The files related to the XSS vulnerability in PrestaShop 1.7.6.2 are AdminQuickAccessesController.php, themes/default/template/header.tpl, and themes/new-theme/js/header.js.
5
How can I fix the XSS vulnerability in PrestaShop 1.7.6.2?
To fix the XSS vulnerability in PrestaShop 1.7.6.2, it is recommended to apply the security patch provided by PrestaShop.