Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-prrh-qvhf-x788: Cross-site Scripting in prestashop/productcomments

Impact

An attacker could steal an admin’s cookie

Patches

The issue is fixed in 5.0.2

References

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)

ghsa
#xss#web#git

Cross-site Scripting in prestashop/productcomments

Moderate severity GitHub Reviewed Published Aug 31, 2022 in PrestaShop/productcomments • Updated Aug 31, 2022

Related news

CVE-2022-35933: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in prestashop/productcomments

This package is a PrestaShop module that allows users to post reviews and rate products. There is a vulnerability where the attacker could steal an administrator's cookie. The issue is fixed in version 5.0.2.