In the ps_link module for PrestaShop before version 3.1.0, there is a stored XSS when you create or edit a link list block with the title field. The problem is fixed in 3.1.0
{ "extracted_events": [ { "introduced": "1.0.4" }, { "fixed": "3.1.0" } ], "source": [ "CPE_RANGE", "REFERENCES" ], "cpe": "cpe:2.3:a:prestashop:prestashop_link:*:*:*:*:*:prestashop:*:*" }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-5266.json"