Medium severity4.1NVD Advisory· Published Mar 25, 2020· Updated Jun 17, 2026
CVE-2020-5277
CVE-2020-5277
Description
PrestaShop module ps_facetedsearch versions before 3.5.0 has a reflected XSS with url_name parameter. The problem is fixed in 3.5.0
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:prestashop:faceted_search_module:*:*:*:*:*:*:*:*Range: >1.0.0,<3.5.0
<3.5.0+ 1 more
- (no CPE)range: <3.5.0
- (no CPE)range: < 3.5.0
Patches
Vulnerability mechanics
References
2- github.com/PrestaShop/ps_facetedsearch/commit/c792ddcdd84ec208a6dfa4a30fd66d8bc9863f4anvdPatchThird Party Advisory
- github.com/PrestaShop/ps_facetedsearch/security/advisories/GHSA-mmmv-m5q9-g3cmnvdThird Party Advisory
News mentions
0No linked articles in our index yet.