Filtered by vendor Prestashop
Subscribe
Total
114 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-5276 | 1 Prestashop | 1 Prestashop | 2023-12-10 | 4.3 MEDIUM | 6.1 MEDIUM |
In PrestaShop between versions 1.7.1.0 and 1.7.6.5, there is a reflected XSS on AdminCarts page with `cartBox` parameter The problem is fixed in 1.7.6.5 | |||||
CVE-2020-15178 | 1 Prestashop | 1 Contactform | 2023-12-10 | 4.3 MEDIUM | 9.3 CRITICAL |
In PrestaShop contactform module (prestashop/contactform) before version 4.3.0, an attacker is able to inject JavaScript while using the contact form. The `message` field was incorrectly unescaped, possibly allowing attackers to execute arbitrary JavaScript in a victim's browser. | |||||
CVE-2020-5279 | 1 Prestashop | 1 Prestashop | 2023-12-10 | 6.4 MEDIUM | 6.5 MEDIUM |
In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for legacy controllers. - admin-dev/index.php/configure/shop/customer-preferences/ - admin-dev/index.php/improve/international/translations/ - admin-dev/index.php/improve/international/geolocation/ - admin-dev/index.php/improve/international/localization - admin-dev/index.php/configure/advanced/performance - admin-dev/index.php/sell/orders/delivery-slips/ - admin-dev/index.php?controller=AdminStatuses The problem is fixed in 1.7.6.5 | |||||
CVE-2020-5273 | 1 Prestashop | 1 Prestashop Linklist | 2023-12-10 | 3.5 LOW | 5.4 MEDIUM |
In PrestaShop module ps_linklist versions before 3.1.0, there is a stored XSS when using custom URLs. The problem is fixed in version 3.1.0 | |||||
CVE-2020-15082 | 1 Prestashop | 1 Prestashop | 2023-12-10 | 7.5 HIGH | 8.8 HIGH |
In PrestaShop from version 1.6.0.1 and before version 1.7.6.6, the dashboard allows rewriting all configuration variables. The problem is fixed in 1.7.6.6 | |||||
CVE-2020-15080 | 1 Prestashop | 1 Prestashop | 2023-12-10 | 5.0 MEDIUM | 5.3 MEDIUM |
In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and others should not be accessible. The problem is fixed in version 1.7.6.6 A possible workaround is to make sure `composer.json` and `docker-compose.yml` are not accessible on your server. | |||||
CVE-2020-5271 | 1 Prestashop | 1 Prestashop | 2023-12-10 | 4.3 MEDIUM | 6.1 MEDIUM |
In PrestaShop between versions 1.6.0.0 and 1.7.6.5, there is a reflected XSS with `date_from` and `date_to` parameters in the dashboard page This problem is fixed in 1.7.6.5 | |||||
CVE-2020-5270 | 1 Prestashop | 1 Prestashop | 2023-12-10 | 5.8 MEDIUM | 6.1 MEDIUM |
In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is an open redirection when using back parameter. The impacts can be many, and vary from the theft of information and credentials to the redirection to malicious websites containing attacker-controlled content, which in some cases even cause XSS attacks. So even though an open redirection might sound harmless at first, the impacts of it can be severe should it be exploitable. The problem is fixed in 1.7.6.5 | |||||
CVE-2020-15079 | 1 Prestashop | 1 Prestashop | 2023-12-10 | 5.5 MEDIUM | 5.4 MEDIUM |
In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module Manager and Module Positions. The problem is fixed in version 1.7.6.6 | |||||
CVE-2020-5285 | 1 Prestashop | 1 Prestashop | 2023-12-10 | 4.3 MEDIUM | 6.1 MEDIUM |
In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is a reflected XSS with `back` parameter. The problem is fixed in 1.7.6.5 | |||||
CVE-2020-4074 | 1 Prestashop | 1 Prestashop | 2023-12-10 | 10.0 HIGH | 9.8 CRITICAL |
In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and execute admin commands. The problem is fixed in 1.7.6.6. | |||||
CVE-2020-5277 | 1 Prestashop | 1 Faceted Search Module | 2023-12-10 | 3.5 LOW | 5.4 MEDIUM |
PrestaShop module ps_facetedsearch versions before 3.5.0 has a reflected XSS with `url_name` parameter. The problem is fixed in 3.5.0 | |||||
CVE-2020-11074 | 1 Prestashop | 1 Prestashop | 2023-12-10 | 3.5 LOW | 5.4 MEDIUM |
In PrestaShop from version 1.5.3.0 and before version 1.7.6.6, there is a stored XSS when using the name of a quick access item. The problem is fixed in 1.7.6.6. | |||||
CVE-2020-5287 | 1 Prestashop | 1 Prestashop | 2023-12-10 | 6.4 MEDIUM | 6.5 MEDIUM |
In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is fixed in 1.7.6.5. | |||||
CVE-2020-15102 | 1 Prestashop | 1 Dashboard Products | 2023-12-10 | 4.0 MEDIUM | 6.5 MEDIUM |
In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to change the configuration. The problem is fixed in 2.1.0. | |||||
CVE-2020-12120 | 1 Prestashop | 1 Correos Express | 2023-12-10 | 5.0 MEDIUM | 7.5 HIGH |
The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such as a service's owner password that can be used to modify orders via SOAP. Attackers can also retrieve information about orders or buyers. | |||||
CVE-2020-5272 | 1 Prestashop | 1 Prestashop | 2023-12-10 | 4.3 MEDIUM | 6.1 MEDIUM |
In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is a reflected XSS on Search page with `alias` and `search` parameters. The problem is patched in 1.7.6.5 | |||||
CVE-2020-5288 | 1 Prestashop | 1 Prestashop | 2023-12-10 | 6.4 MEDIUM | 6.5 MEDIUM |
"In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there is improper access controls on product attributes page. The problem is fixed in 1.7.6.5. | |||||
CVE-2020-5265 | 1 Prestashop | 1 Prestashop | 2023-12-10 | 4.3 MEDIUM | 6.1 MEDIUM |
In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminAttributesGroups page. The problem is patched in 1.7.6.5. | |||||
CVE-2020-5269 | 1 Prestashop | 1 Prestashop | 2023-12-10 | 4.3 MEDIUM | 6.1 MEDIUM |
In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feature` parameter. The problem is fixed in 1.7.6.5 |