Server side cross-site scripting In prestashop/prestashop

Description

PrestaShop has a stored XSS executable in customer service view

Impact

This is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view.

An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover.

Patches

Patched in PrestaShop 8.2.6 and 9.1.1.

Workarounds

None.

Resources

    Reported by Savio at Doyensec ([email protected]) in collaboration with Anthropic Research.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions