CVE-2018-5681: XSS
Published Jan 13, 2018
·Updated
PrestaShop 1.7.2.4 has XSS via source-code editing on the "Pages > Edit page" screen.
Affected Software
1 affected component
Prestashop PrestaShop=1.7.2.4
Event History
Jan 13, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Data Sourced
via NVD·05:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-5681?
The severity of CVE-2018-5681 is classified as medium due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2018-5681?
To fix CVE-2018-5681, upgrade PrestaShop to version 1.7.2.5 or later, which includes a patch for this vulnerability.
3
Which versions of PrestaShop are affected by CVE-2018-5681?
CVE-2018-5681 affects PrestaShop version 1.7.2.4 specifically.
4
What type of vulnerability is CVE-2018-5681?
CVE-2018-5681 is categorized as a cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2018-5681?
Attackers exploiting CVE-2018-5681 can inject malicious scripts through the source-code editing feature, potentially compromising user data.