In PrestaShop from version 1.5.0.0 and before version 1.7.6.8, users are allowed to send compromised files. These attachments allowed people to input malicious JavaScript which triggered an XSS payload. The problem is fixed in version 1.7.6.8.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/PrestaShop/PrestaShop/releases/tag/1.7.6.8 | third party advisory |
https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-rc8c-v7rq-q392 | third party advisory exploit |
https://github.com/PrestaShop/PrestaShop/commit/2cfcd33c75974a49f17665f294f228454e14d9cf | third party advisory patch |