PrestaShop Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2020-15160 - Vulnerability Database

PrestaShop Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2020-15160

Critical
Reference: CVE-2020-15160
Title: PrestaShop Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:

PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog Product edition page with location parameter. The problem is fixed in 1.7.6.8