CVE-2020-5277 Information
Feb 14, 2021
cve
Description
PrestaShop module ps_facetedsearch versions before 3.5.0 has a reflected XSS with url_name parameter. The problem is fixed in 3.5.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
https://github.com/PrestaShop/ps_facetedsearch/commit/c792ddcdd84ec208a6dfa4a30fd66d8bc9863f4a
https://github.com/PrestaShop/ps_facetedsearch/security/advisories/GHSA-mmmv-m5q9-g3cm
PrestaShop
module
ps_facetedsearch
versions
before
3.5.0
has
a
reflected
XSS
with
url_name
parameter.
The
problem
is
fixed
in
3.5.0
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: