Reflected XSS with parameters in PostComment
Moderate severity
GitHub Reviewed
Published
Nov 16, 2020
in
PrestaShop/productcomments
•
Updated Jan 9, 2023
Package
Affected versions
>= 4.0.0, < 4.2.0
Patched versions
4.2.0
Description
Reviewed
Nov 16, 2020
Published to the GitHub Advisory Database
Nov 16, 2020
Last updated
Jan 9, 2023
Impact
An attacker could inject malicious web code into the users' web browsers by creating a malicious link.
Patches
The problem is fixed in 4.2.0
References
Cross-site Scripting (XSS) - Reflected (CWE-79)
References