CVE-2025-24027 – prestashop/ps_contactinfo
Package
Manager: composer
Name: prestashop/ps_contactinfo
Vulnerable Version: >=0 <3.3.3
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00053 pctl0.16389
Details
ps_contactinfo has a potential XSS due to usage of the nofilter tag in template ### Impact This can not be exploited in a fresh install of PrestaShop, only shops made vulnerable by third party modules are concerned. For example, if your shop has a third party module vulnerable to SQL injections, then ps_contactinfo might execute a stored XSS in FO. ### Patches The long term fix is to have all your modules maintained and updated. The fix on ps_contactinfo will keep formatted addresses from displaying an xss stored in the database. ### Workarounds none ### References none
Metadata
Created: 2025-01-22T18:10:58Z
Modified: 2025-01-22T18:10:58Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-35pq-7pv2-2rfw/GHSA-35pq-7pv2-2rfw.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-35pq-7pv2-2rfw
Finding: F425
Auto approve: 1