In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the contact form. The problem is fixed in 1.7.6.8
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published: 2020-09-24T22:10:13
Updated: 2024-08-04T13:08:22.256Z
Reserved: 2020-06-25T00:00:00
Link: CVE-2020-15161
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2020-09-24T22:15:12.260
Modified: 2024-11-21T05:04:58.563
Link: CVE-2020-15161
 Redhat
                        Redhat
                    No data.