PT-2020-16354 · Prestashop · Prestashop Product Comments

My3Ker

·

Published

2020-11-16

·

Updated

2020-11-30

·

CVE-2020-26225

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PrestaShop Product Comments versions 4.0.0 through 4.2.0
Description An attacker could inject malicious web code into the users' web browsers by creating a malicious link. The problem was introduced in version 4.0.0 and is fixed in 4.2.0.
Recommendations For PrestaShop Product Comments versions 4.0.0 through 4.1.x, update to version 4.2.0 to resolve the issue. As a temporary workaround, consider restricting user input to prevent malicious link creation until a patch is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26225
GHSA-58W4-W77W-QV3W

Affected Products

Prestashop Product Comments