First published: Sat Jan 13 2018(Updated: )
PrestaShop 1.7.2.4 has XSS via source-code editing on the "Pages > Edit page" screen.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Prestashop | =1.7.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-5681 is classified as medium due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2018-5681, upgrade PrestaShop to version 1.7.2.5 or later, which includes a patch for this vulnerability.
CVE-2018-5681 affects PrestaShop version 1.7.2.4 specifically.
CVE-2018-5681 is categorized as a cross-site scripting (XSS) vulnerability.
Attackers exploiting CVE-2018-5681 can inject malicious scripts through the source-code editing feature, potentially compromising user data.