Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vwfx-hh3w-fj99

Опубликовано: 06 апр. 2021
Источник: github
Github: Прошло ревью
CVSS3: 4.6

Описание

Potential XSS injection in the newsletter conditions field

Impact

An employee can inject javascript in the newsletter condition field that will then be executed on the front office

Patches

The issue has been fixed in 2.6.1

Пакеты

Наименование

prestashop/ps_emailsubscription

composer
Затронутые версииВерсия исправления

< 2.6.1

2.6.1

EPSS

Процентиль: 50%
0.00264
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.6
nvd
почти 5 лет назад

ps_emailsubscription is a newsletter subscription module for the PrestaShop platform. An employee can inject javascript in the newsletter condition field that will then be executed on the front office The issue has been fixed in 2.6.1

EPSS

Процентиль: 50%
0.00264
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-79