CVE-2021-21398: Possible XSS injection through DataColumn Grid class
Published Mar 30, 2021
·Updated
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.7.3, an attacker can inject HTML when the Grid Column Type DataColumn is badly used. The problem is fixed in 1.7.7.3
Affected Software
1 affected component
Prestashop PrestaShop>=1.7.7.0<1.7.7.3
Remediation
Event History
Mar 30, 2021
CVE Published
via MITRE·03:25 PM
Data Sourced
via MITRE·03:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-21398?
CVE-2021-21398 is a vulnerability in PrestaShop e-commerce solution where an attacker can inject HTML when the Grid Column Type DataColumn is badly used.
2
What is the severity of CVE-2021-21398?
The severity of CVE-2021-21398 is medium with a base score of 5.4.
3
How can an attacker exploit CVE-2021-21398?
An attacker can exploit CVE-2021-21398 by injecting malicious HTML when the Grid Column Type DataColumn is misused.
4
How can I fix CVE-2021-21398?
To fix CVE-2021-21398, update PrestaShop to version 1.7.7.3 or later.
5
Where can I find more information about CVE-2021-21398?
You can find more information about CVE-2021-21398 in the links provided: [link1], [link2], [link3].