CVE-2020-15161 Vulnerability Details
/
/
/
CVE-2020-15161 Metadata Quick Info
CVE Published: 24/09/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020
Source: GitHub_M |
Vendor: PrestaShop |
Product: PrestaShop
Status : PUBLISHED
CVE-2020-15161 Description
In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the contact form. The problem is fixed in 1.7.6.8
Metrics
CVSS Version: 3.1 |
Base Score: 5.4 MEDIUM
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
l➤ Exploitability Metrics:
Attack Vector (AV)* NETWORK
Attack Complexity (AC)* HIGH
Privileges Required (PR)* NONE
User Interaction (UI)* NONE
Scope (S)* CHANGED
l➤ Impact Metrics:
Confidentiality Impact (C)* LOW
Integrity Impact (I)* LOW
Availability Impact (A)* NONE
Weakness Enumeration (CWE)
CWE-ID: CWE-79
CWE Name: CWE-79: Improper Neutralization of Input During Web Page Generation (
Cross-site Scripting
)
Source: PrestaShop
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).