CVE-2020-15178
15.09.2020, 18:15
In PrestaShop contactform module (prestashop/contactform) before version 4.3.0, an attacker is able to inject JavaScript while using the contact form. The `message` field was incorrectly unescaped, possibly allowing attackers to execute arbitrary JavaScript in a victim's browser.
Vendor | Product | Version |
---|---|---|
prestashop | contactform | 𝑥 < 4.3.0 |
𝑥
= Vulnerable software versions
References