CVE-2012-2517
Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of the product[] parameter to ajax.php.
- Affected products
- Prestashop
- Prestashop
- < 1.4.9.0
- Fix
- Available
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 1.9% (78th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2020-02-11
CVE-2012-2517 at NVD
3 known exploits for CVE-2012-2517
Proof-of-concept code and exploit modules indexed by Sploitus