VYPR
Medium severity6.1NVD Advisory· Published Dec 21, 2021· Updated Jun 16, 2026

CVE-2012-20001

CVE-2012-20001

Description

PrestaShop before 1.5.2 allows XSS via the "<object data='data:text/html" substring in the message field.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
prestashop/prestashopPackagist
< 1.5.2.01.5.2.0

Affected products

3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.