Server side cross-site scripting In prestashop/prestashop
Description
PrestaShop has a stored XSS executable in customer service view
Impact
This is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view.
An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover.
Patches
Patched in PrestaShop 8.2.6 and 9.1.1.
Workarounds
None.
Resources
Reported by Savio at Doyensec ([email protected]) in collaboration with Anthropic Research.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | prestashop/prestashop | 8.2.6, 9.1.1 |
Aliases
References