PT-2020-16354 · Prestashop · Prestashop Product Comments
My3Ker
·
Published
2020-11-16
·
Updated
2020-11-30
·
CVE-2020-26225
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PrestaShop Product Comments versions 4.0.0 through 4.2.0
Description
An attacker could inject malicious web code into the users' web browsers by creating a malicious link. The problem was introduced in version 4.0.0 and is fixed in 4.2.0.
Recommendations
For PrestaShop Product Comments versions 4.0.0 through 4.1.x, update to version 4.2.0 to resolve the issue.
As a temporary workaround, consider restricting user input to prevent malicious link creation until a patch is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prestashop Product Comments