CVE-2020-26225

In PrestaShop Product Comments before version 4.2.0, an attacker could inject malicious web code into the users' web browsers by creating a malicious link. The problem was introduced in version 4.0.0 and is fixed in 4.2.0
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:prestashop:product_comments:*:*:*:*:*:*:*:*

Information

Published : 2020-11-16 14:15

Updated : 2020-11-30 10:36


NVD link : CVE-2020-26225

Mitre link : CVE-2020-26225


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

prestashop

  • product_comments