Description PrestaShop before 1.5.2 allows XSS via the "<object data='data:text/html" substring in the message field. Remediation References CVE-2012-20001 Related Vulnerabilities WordPress Plugin WP Dark Mode-Best Dark Mode & Social Sharing for WordPress Cross-Site Scripting (3.0.6) Elgg Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6562) WordPress Plugin WooCommerce Social Login PHP Object Injection (2.6.3) Magento Insufficient Session Expiration Vulnerability (CVE-2019-8149) Oracle Database Server CVE-2009-1972 Vulnerability (CVE-2009-1972) Severity Medium Classification CVE-2012-20001 CWE-707 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities