ps_emailsubscription is a newsletter subscription module for the PrestaShop platform. An employee can inject javascript in the newsletter condition field that will then be executed on the front office The issue has been fixed in 2.6.1
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/PrestaShop/ps_emailsubscription/security/advisories/GHSA-vwfx-hh3w-fj99 | third party advisory |
https://github.com/PrestaShop/ps_emailsubscription/commit/664ffb225e2afb4a32640bbedad667dc6e660b70 | third party advisory patch |
https://github.com/PrestaShop/ps_emailsubscription/releases/tag/v2.6.1 | third party advisory release notes |
https://packagist.org/packages/prestashop/ps_emailsubscription | third party advisory |