Cross-Site Scripting Vulnerability in PrestaShop Module by PrestaShop
CVE-2025-24027
What is CVE-2025-24027?
The ps_contactinfo module for PrestaShop, which manages store contact information display, is vulnerable to cross-site scripting (XSS) in all versions up to and including 3.3.2. This vulnerability occurs in shops that have additional third-party modules installed, specifically those with vulnerabilities such as SQL injection, allowing attackers to execute stored XSS via improperly formatted address objects. A critical commit has been made to rectify this issue, and users are urged to upgrade to version 3.3.3 or later to mitigate the risk. Immediate application of security patches is recommended, and maintaining all modules is crucial to maintain site security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ps_contactinfo <= 3.3.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
