PrestaShop是美国PrestaShop公司的一套开源的电子商务解决方案。该方案提供多种支付方式、短消息提醒和商品图片缩放等功能。 PrestaShop 1.5.4.0之后版本(1.7.6.5版本已修复)中的异常页面存在跨站脚本漏洞。该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PrestaShop | PrestaShop | >= 1.5.4.0, < 1.7.6.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-5293 | 6.5 MEDIUM | Improper access control on product page with combinations, attachments and specific prices |
| CVE-2020-5264 | 4.4 MEDIUM | Reflected XSS in security compromised page of PrestaShop |
| CVE-2020-5265 | 4.4 MEDIUM | Reflected XSS on AdminAttributesGroups page of PrestaShop |
| CVE-2020-5269 | 4.1 MEDIUM | Reflected XSS on AdminFeatures page of PrestaShop |
| CVE-2020-5270 | 4.1 MEDIUM | Open redirection when using back parameter of PrestaShop |
| CVE-2020-5271 | 4.1 MEDIUM | Reflected XSS with dashboard calendar of PrestaShop |
| CVE-2020-5272 | 4.1 MEDIUM | Reflected XSS on Search page of PrestaShop |
| CVE-2020-5276 | 4.1 MEDIUM | Reflected XSS on AdminCarts page of PrestaShop |
| CVE-2020-5279 | 4.1 MEDIUM | Improper Access Control for certain legacy controller in PrestaShop |
| CVE-2020-5285 | 4.1 MEDIUM | Reflected XSS with back parameter in PrestaShop |
| CVE-2020-5286 | 4.1 MEDIUM | Reflected XSS related in import page in PrestaShop |
| CVE-2020-5287 | 4.1 MEDIUM | Improper access control on customers search in PrestaShop |
| CVE-2020-5288 | 4.1 MEDIUM | Improper access control on product attributes page in PrestaShop |
No comments yet