CVE-2020-26225

In PrestaShop Product Comments before version 4.2.0, an attacker could inject malicious web code into the users' web browsers by creating a malicious link. The problem was introduced in version 4.0.0 and is fixed in 4.2.0
Configurations

Configuration 1 (hide)

cpe:2.3:a:prestashop:product_comments:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-11-16 22:15

Updated : 2024-02-28 18:08


NVD link : CVE-2020-26225

Mitre link : CVE-2020-26225

CVE.ORG link : CVE-2020-26225


JSON object : View

Products Affected

prestashop

  • product_comments
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')