CVE-2021-21418: Potential XSS injection in the newsletter conditions field
Published Mar 31, 2021
·Updated
psemailsubscription is a newsletter subscription module for the PrestaShop platform. An employee can inject javascript in the newsletter condition field that will then be executed on the front office The issue has been fixed in 2.6.1
Affected Software
1 affected component
Prestashop Ps Emailsubscription Prestashop>=2.6.0<2.6.1
Remediation
Event History
Mar 31, 2021
CVE Published
via MITRE·05:35 PM
Data Sourced
via MITRE·05:35 PM
DescriptionSeverityWeakness