VulnerabilityModified
CVE-2020-15162
In PrestaShop from version 1.5.0.0 and before version 1.7.6.8, users are allowed to send compromised files.
MEDIUM 5.4EPSS 0.80%
Does this matter?
Lower severity and a low EPSS score (0.80%). Track it; it rarely justifies an emergency change on its own.
Description
In PrestaShop from version 1.5.0.0 and before version 1.7.6.8, users are allowed to send compromised files. These attachments allowed people to input malicious JavaScript which triggered an XSS payload. The problem is fixed in version 1.7.6.8.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.80% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- prestashop/prestashop
- Source
- security-advisories@github.com
References
- https://github.com/PrestaShop/PrestaShop/commit/2cfcd33c75974a49f17665f294f228454e14d9cfPatch, Third Party Advisory
- https://github.com/PrestaShop/PrestaShop/releases/tag/1.7.6.8Third Party Advisory
- https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-rc8c-v7rq-q392Exploit, Third Party Advisory
- https://github.com/PrestaShop/PrestaShop/commit/2cfcd33c75974a49f17665f294f228454e14d9cfPatch, Third Party Advisory
- https://github.com/PrestaShop/PrestaShop/releases/tag/1.7.6.8Third Party Advisory
- https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-rc8c-v7rq-q392Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.