CVE-2019-11876: XSS
In PrestaShop 1.7.5.2, the shopcountry parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and conditions) before executing the malicious link.
Other sources
In PrestaShop 1.7.5.2, the shopcountry parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and conditions) before executing the malicious link.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11876?
CVE-2019-11876 is a vulnerability in PrestaShop 1.7.5.2 that allows for Reflected XSS attacks.
What is the severity of CVE-2019-11876?
The severity of CVE-2019-11876 is medium, with a CVSS score of 6.1.
How does CVE-2019-11876 affect PrestaShop 1.7.5.2?
CVE-2019-11876 affects PrestaShop 1.7.5.2 by allowing for Reflected XSS attacks through the shop_country parameter in the installation script.
How can CVE-2019-11876 be exploited?
Exploiting CVE-2019-11876 requires the user to follow the initial stages of the setup (accepting terms and conditions) before executing a malicious link.
Is Drupal 8.7.0 affected by CVE-2019-11876?
No, CVE-2019-11876 only affects PrestaShop 1.7.5.2.