PT-2022-23039 · Unknown · Prestashop

Atomiix

·

Published

2022-08-31

·

Updated

2022-09-08

·

CVE-2022-35933

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PrestaShop module versions prior to 5.0.2
Description The issue allows an attacker to steal an administrator's cookie, potentially leading to unauthorized access. The problem is related to improper neutralization of input during web page generation, which can facilitate cross-site scripting attacks.
Recommendations For versions prior to 5.0.2, update to version 5.0.2 to resolve the issue. As a temporary workaround, consider restricting access to administrator accounts until the update can be applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-35933
GHSA-PRRH-QVHF-X788

Affected Products

Prestashop