Cross-site scripting in PrestaShop - CVE-2020-11074
Published: July 2, 2020 / Updated: May 4, 2026
PrestaShop
PrestaShop SA
Description
The vulnerability allows a remote user to execute arbitrary script code in a user's browser.
The vulnerability exists due to cross-site scripting in AdminQuickAccesses when processing the name of a quick access item. A remote user can create or modify a quick access item with a specially crafted name to execute arbitrary script code in a user's browser.