PT-2023-26998 · Unknown · Prestashop

Aleksey Solovev

·

Published

2023-08-07

·

Updated

2024-03-06

·

CVE-2023-39527

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions PrestaShop versions prior to 1.7.8.10 PrestaShop versions prior to 8.0.5 PrestaShop versions prior to 8.1.1
Description PrestaShop is an open source e-commerce web application. The issue concerns cross-site scripting through the isCleanHTML method. There are no known workarounds.
Recommendations For PrestaShop versions prior to 1.7.8.10, update to version 1.7.8.10 to resolve the issue. For PrestaShop versions prior to 8.0.5, update to version 8.0.5 to resolve the issue. For PrestaShop versions prior to 8.1.1, update to version 8.1.1 to resolve the issue.

Exploit

Fix

Improper Encoding or Escaping of Output

XSS

Weakness Enumeration

Related Identifiers

BIT-PRESTASHOP-2023-39527
CVE-2023-39527
GHSA-XW2R-F8XV-C8XP

Affected Products

Prestashop