Medium severity5.4NVD Advisory· Published Sep 24, 2020· Updated Jun 17, 2026
CVE-2020-15161
CVE-2020-15161
Description
In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the contact form. The problem is fixed in 1.7.6.8
Affected products
3cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*range: >=1.6.0.4,<1.7.6.8
- (no CPE)range: 1.6.0.4 - 1.7.6.7
- (no CPE)range: > 1.6.0.4, < 1.7.6.8
Patches
Vulnerability mechanics
References
3- github.com/PrestaShop/PrestaShop/commit/562a231fec18a928e4a601860416fe11af274672nvdPatchThird Party Advisory
- github.com/PrestaShop/PrestaShop/releases/tag/1.7.6.8nvdThird Party Advisory
- github.com/PrestaShop/PrestaShop/security/advisories/GHSA-5cp2-r794-w37wnvdThird Party Advisory
News mentions
0No linked articles in our index yet.