PrestaShop Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2012-20001 - Vulnerability Database

PrestaShop Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2012-20001

Medium
Reference: CVE-2012-20001
Title: PrestaShop Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

PrestaShop before 1.5.2 allows XSS via the quotltobject data39data:text/htmlquot substring in the message field.