CVE-2020-15160
PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog Product edition page with location parameter. The problem is fixed in 1.7.6.8
- Affected products
- Prestashop
- Prestashop
- < 1.7.6.8
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 10.8% (95th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2020-09-24
CVE-2020-15160 at NVD
3 known exploits for CVE-2020-15160
Proof-of-concept code and exploit modules indexed by Sploitus