Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-21627

Опубликовано: 02 янв. 2024
Источник: nvd
CVSS3: 8.1
CVSS3: 6.1
EPSS Низкий

Описание

PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not detected by the isCleanHTML method. Some modules using the isCleanHTML method could be vulnerable to cross-site scripting. Versions 8.1.3 and 1.7.8.11 contain a patch for this issue. The best workaround is to use the HTMLPurifier library to sanitize html input coming from users. The library is already available as a dependency in the PrestaShop project. Beware though that in legacy object models, fields of HTML type will call isCleanHTML.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*
Версия до 1.7.8.11 (исключая)
cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*
Версия от 8.0.0 (включая) до 8.1.3 (исключая)

EPSS

Процентиль: 76%
0.0095
Низкий

8.1 High

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-20
CWE-79

Связанные уязвимости

CVSS3: 8.1
github
около 2 лет назад

PrestaShop some attribute not escaped in Validate::isCleanHTML method

EPSS

Процентиль: 76%
0.0095
Низкий

8.1 High

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-20
CWE-79