CVE-2012-20001: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
(updated )
PrestaShop before 1.5.2 allows XSS via the “<object data=‘data:text/html” substring in the message field.
References
Detect and mitigate CVE-2012-20001 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →