PT-2024-21153 · Common Services+1 · So Flexibilite+1

Published

2024-02-27

·

Updated

2024-02-28

·

CVE-2024-25841

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions PrestaShop versions prior to 4.1.26
Description The issue allows a guest or authenticated customer to perform Cross Site Scripting (XSS) injection in the "So Flexibilite" module from Common-Services.
Recommendations For PrestaShop versions prior to 4.1.26, update to version 4.1.26 or later to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-25841

Affected Products

Prestashop
So Flexibilite