Medium severity5.4NVD Advisory· Published Sep 24, 2020· Updated Jun 17, 2026
CVE-2020-15162
CVE-2020-15162
Description
In PrestaShop from version 1.5.0.0 and before version 1.7.6.8, users are allowed to send compromised files. These attachments allowed people to input malicious JavaScript which triggered an XSS payload. The problem is fixed in version 1.7.6.8.
Affected products
3cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*range: >=1.5.0.0,<1.7.6.8
- (no CPE)range: 1.5.0.0 <= version < 1.7.6.8
- (no CPE)range: > 1.5.0.0, < 1.7.6.8
Patches
Vulnerability mechanics
References
3- github.com/PrestaShop/PrestaShop/commit/2cfcd33c75974a49f17665f294f228454e14d9cfnvdPatchThird Party Advisory
- github.com/PrestaShop/PrestaShop/security/advisories/GHSA-rc8c-v7rq-q392nvdExploitThird Party Advisory
- github.com/PrestaShop/PrestaShop/releases/tag/1.7.6.8nvdThird Party Advisory
News mentions
0No linked articles in our index yet.