VYPR
Medium severity5.4NVD Advisory· Published Sep 24, 2020· Updated Jun 17, 2026

CVE-2020-15161

CVE-2020-15161

Description

In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the contact form. The problem is fixed in 1.7.6.8

Affected products

3
  • cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*range: >=1.6.0.4,<1.7.6.8
    • (no CPE)range: 1.6.0.4 - 1.7.6.7
    • (no CPE)range: > 1.6.0.4, < 1.7.6.8

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.