NA

CVE-2023-39527

Published: 07/08/2023 Updated: 09/08/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

PrestaShop is an open source e-commerce web application. Versions before 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to cross-site scripting through the `isCleanHTML` method. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

prestashop prestashop 8.1.0

prestashop prestashop

Github Repositories

Prestashop fix vulnerability CVE-2023-39526 & CVE-2023-39527

fix CVE 2023_39526 (GHSA-gf46-prm4-56pc) githubcom/advisories/GHSA-gf46-prm4-56pc CVE 2023_39527 (GHSA-xw2r-f8xv-c8xp) githubcom/advisories/GHSA-xw2r-f8xv-c8xp Prestashop fix vulnerability CVE-2023-39526 & CVE-2023-39527