CVE-2020-15178

Published

Severity

CVSS v3:
9.3 CRITICAL
CVSS v2:
4.3 MEDIUM

Description

In PrestaShop contactform module (prestashop/contactform) before version 4.3.0, an attacker is able to inject JavaScript while using the contact form. The `message` field was incorrectly unescaped, possibly allowing attackers to execute arbitrary JavaScript in a victim's browser.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:prestashop:contactform:*:*:*:*:*:prestashop:*:*n/a4.3.0*

External Links