Security Advisory
CVE-2020-15161
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the contact form. The problem is fixed in 1.7.6.8