Search Results (Refine Search)
- Keyword (text search): cpe:2.3:a:prestashop:contactform:4.0.0:*:*:*:*:prestashop:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2020-15178 |
In PrestaShop contactform module (prestashop/contactform) before version 4.3.0, an attacker is able to inject JavaScript while using the contact form. The `message` field was incorrectly unescaped, possibly allowing attackers to execute arbitrary JavaScript in a victim's browser. Published: September 15, 2020; 2:15:13 PM -0400 |
V4.0:(not available) V3.1: 9.3 CRITICAL V2.0: 4.3 MEDIUM |