PT-2024-18978 · Unknown · Prestashop

Antonio-R1

+1

·

Published

2024-01-02

·

Updated

2024-03-06

·

CVE-2024-21627

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PrestaShop versions prior to 8.1.3 PrestaShop versions prior to 1.7.8.11
Description PrestaShop is an open-source e-commerce platform. Some event attributes are not detected by the isCleanHTML method, which could make some modules using this method vulnerable to cross-site scripting.
Recommendations For versions prior to 8.1.3, update to version 8.1.3 to resolve the issue. For versions prior to 1.7.8.11, update to version 1.7.8.11 to resolve the issue. As a temporary workaround, consider using the HTMLPurifier library to sanitize HTML input coming from users, as it is already available as a dependency in the PrestaShop project. Be aware that in legacy object models, fields of HTML type will call isCleanHTML.

Exploit

Fix

RCE

XSS

Weakness Enumeration

Related Identifiers

BIT-PRESTASHOP-2024-21627
CVE-2024-21627
GHSA-XGPM-Q3MQ-46RQ

Affected Products

Prestashop