VYPR
Medium severity6.1NVD Advisory· Published Feb 11, 2020· Updated Jun 16, 2026

CVE-2012-2517

CVE-2012-2517

Description

Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of the product[] parameter to ajax.php.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*range: <1.4.9.0
    • (no CPE)range: <1.4.9
  • PrestaShop/PrestaShopdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.