CVE-2012-20001
PrestaShop before 1.5.2 allows XSS via the "<object data='data:text/html" substring in the message field.
PrestaShop before 1.5.2 allows XSS via the "<object data='data:text/html" substring in the message field.
MEDIUM · CVSS 6.1
EPSS 0.00401
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0