First published: Fri Mar 20 2009(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in PrestaShop 1.1.0.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin/login.php and (2) order.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Prestashop Prestashop | =1.1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6503 is associated with multiple cross-site scripting (XSS) vulnerabilities in PrestaShop that allow remote attackers to inject arbitrary web scripts or HTML.
PrestaShop version 1.1.0.3 is affected by the vulnerabilities described in CVE-2008-6503.
To mitigate CVE-2008-6503, you should upgrade to a newer, secure version of PrestaShop that addresses these vulnerabilities.
The vulnerabilities in CVE-2008-6503 can be exploited via the admin/login.php and order.php paths in PrestaShop.
The impact of CVE-2008-6503 includes potential unauthorized script execution in the context of user sessions, leading to data theft or session hijacking.