Beveiligingsadvies

CVE-2020-15178

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-09-15 17:50:13
Laatst bijgewerkt 2024-08-04 13:08:22
Toegewezen door GitHub_M
CVSS-score 8.0
Status PUBLISHED

Beschrijving

In PrestaShop contactform module (prestashop/contactform) before version 4.3.0, an attacker is able to inject JavaScript while using the contact form. The `message` field was incorrectly unescaped, possibly allowing attackers to execute arbitrary JavaScript in a victim's browser.