logo

CVE-2025-24027 prestashop/ps_contactinfo

Package

Manager: composer
Name: prestashop/ps_contactinfo
Vulnerable Version: >=0 <3.3.3

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00053 pctl0.16389

Details

ps_contactinfo has a potential XSS due to usage of the nofilter tag in template ### Impact This can not be exploited in a fresh install of PrestaShop, only shops made vulnerable by third party modules are concerned. For example, if your shop has a third party module vulnerable to SQL injections, then ps_contactinfo might execute a stored XSS in FO. ### Patches The long term fix is to have all your modules maintained and updated. The fix on ps_contactinfo will keep formatted addresses from displaying an xss stored in the database. ### Workarounds none ### References none

Metadata

Created: 2025-01-22T18:10:58Z
Modified: 2025-01-22T18:10:58Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-35pq-7pv2-2rfw/GHSA-35pq-7pv2-2rfw.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-35pq-7pv2-2rfw
Finding: F425
Auto approve: 1