CVE-2015-1175
Cross-site scripting (XSS) vulnerability in blocklayered-ajax.php in the blocklayered module in PrestaShop 1.6.0.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the layered_price_slider parameter.
- Affected products
- Prestashop
- Prestashop
- ≤ 1.6.0.9
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 1.9% (79th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2015-01-22
CVE-2015-1175 at NVD
2 known exploits for CVE-2015-1175
Proof-of-concept code and exploit modules indexed by Sploitus