PrestaShop XSS vulnerability through Validate::isCleanHTML method
CVE-2023-39527
8.3HIGH
What is CVE-2023-39527?
PrestaShop, a widely-used open source e-commerce web application, is susceptible to cross-site scripting (XSS) attacks in versions before 1.7.8.10, 8.0.5, and 8.1.1 due to flaws in the isCleanHTML
method. This vulnerability allows malicious users to inject arbitrary scripts into the web app, compromising the integrity of the application and potentially impacting end-users. Users are advised to upgrade to the patched versions to mitigate risks. No workarounds are available for this vulnerability.
Affected Version(s)
PrestaShop < 1.7.8.10 < 1.7.8.10
PrestaShop >= 8.0.0, < 8.0.5 < 8.0.0, 8.0.5
PrestaShop = 8.1.0 = 8.1.0
References
CVSS V3.1
Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved