CVE-2020-5270 describes an open redirection vulnerability in PrestaShop versions 1.7.6.0 through 1.7.6.5, specifically when the "back" parameter is used. This medium-severity vulnerability (CVSS 6.1) can lead to information theft, credential compromise, or redirection to malicious websites, potentially enabling XSS attacks. The issue is client-side exploitable via a network vector with low attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
> 1.7.6.0, < 1.7.6.5CPE matchmatch criteria | cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.