In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the contact form. The problem is fixed in 1.7.6.8
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2020-09-24T22:10:13
Updated: 2024-08-04T13:08:22.256Z
Reserved: 2020-06-25T00:00:00
Link: CVE-2020-15161
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-09-24T22:15:12.260
Modified: 2024-11-21T05:04:58.563
Link: CVE-2020-15161
Redhat
No data.