CVEs Blog | G5 Cyber Security

CVE-2020-15178 – In PrestaShop contactform module (prestashop/contactform) before version

In PrestaShop contactform module (prestashop/contactform) before version 4.3.0, an attacker is able to inject JavaScript while using the contact form. The `message` field was incorrectly unescaped, possibly allowing attackers to execute arbitrary JavaScript in a victim’s browser.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15178

Reference (s):

Exit mobile version