Server side cross-site scripting In prestashop/prestashop
Description
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
Impact
Multiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates.
Patches
Patched on 8.2.5 and 9.1.0
Workarounds
None
References
None
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 9.1.0, 8.2.5 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.