PT-2020-18367 · Prestashop · Ps Facetedsearch

Pierre Rambaud

·

Published

2020-03-25

·

Updated

2020-03-27

·

CVE-2020-5277

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PrestaShop module ps facetedsearch versions prior to 3.5.0
Description The issue is related to a reflected XSS with the url name parameter. The problem is fixed in version 3.5.0.
Recommendations For PrestaShop module ps facetedsearch versions prior to 3.5.0, update to version 3.5.0 to resolve the issue. As a temporary workaround, consider restricting the use of the url name parameter in the affected module until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5277
GHSA-MMMV-M5Q9-G3CM

Affected Products

Ps Facetedsearch