CVE-2023-39527: PrestaShop XSS vulnerability through Validate::isCleanHTML method
Impact xss injection through isCleanHTML method
Patches 1.7.8.10 8.0.5 8.1.1
Found by Aleksey Solovev (Positive Technologies)
Workarounds
References
Other sources
PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to cross-site scripting through the isCleanHTML method. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this PrestaShop cross-site scripting vulnerability?
The vulnerability ID for this PrestaShop cross-site scripting vulnerability is CVE-2023-39527.
What is the severity of CVE-2023-39527?
CVE-2023-39527 has a severity rating of 8.3, which is considered high.
How can I exploit the cross-site scripting vulnerability in PrestaShop?
As a cybersecurity analyst, I cannot provide instructions on how to exploit vulnerabilities. It is important to prioritize security and report vulnerabilities to the developers.
I am using PrestaShop version 1.7.8. What should I do to fix CVE-2023-39527?
To fix CVE-2023-39527 in PrestaShop version 1.7.8, update to version 1.7.8.10 or apply the available patch.
Are there any known workarounds for CVE-2023-39527?
There are no known workarounds for CVE-2023-39527. It is important to update to the patched versions or apply the provided patches.