CVE-2020-15162

MEDIUM

PrestaShop 1.5.0.0-1.7.6.8 - Stored Cross-Site Scripting via File Attachment

Title source: llm
STIX 2.1

Description

In PrestaShop from version 1.5.0.0 and before version 1.7.6.8, users are allowed to send compromised files. These attachments allowed people to input malicious JavaScript which triggered an XSS payload. The problem is fixed in version 1.7.6.8.

References (3)

Core 3

Scores

CVSS v3 5.4
EPSS 0.0079
EPSS Percentile 51.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
prestashop/prestashop 1.5.0.0 - 1.7.6.8
Published Sep 24, 2020
Tracked Since Feb 18, 2026