In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and conditions) before executing the malicious link.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.prestashop.com/forums/forum/2-prestashop-news-and-releases/ | release notes vendor advisory |
https://www.logicallysecure.com/blog/xss-presta-xss-drupal/ | exploit vendor advisory |