Medium severity6.1NVD Advisory· Published Dec 21, 2021· Updated Jun 16, 2026
CVE-2012-20001
CVE-2012-20001
Description
PrestaShop before 1.5.2 allows XSS via the "<object data='data:text/html" substring in the message field.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
prestashop/prestashopPackagist | < 1.5.2.0 | 1.5.2.0 |
Affected products
3- PrestaShop/PrestaShopdescription
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-j33m-2537-86jmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2012-20001ghsaADVISORY
- seclists.org/bugtraq/2012/Nov/1nvdMailing ListThird Party AdvisoryWEB
- web.archive.org/web/20140803034142/http://forge.prestashop.com/browse/PSCFV-5204ghsaWEB
- web.archive.org/web/20160305224628/http://davidsopas.com/labs/prestashop_xss.txtghsaWEB
News mentions
0No linked articles in our index yet.