First published: Mon Aug 07 2023(Updated: )
### Impact xss injection through `isCleanHTML` method ### Patches 1.7.8.10 8.0.5 8.1.1 ### Found by Aleksey Solovev (Positive Technologies) ### Workarounds ### References
Credit: security-advisories@github.com security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Prestashop Prestashop | <1.7.8.10 | |
Prestashop Prestashop | >=8.0.0<8.0.5 | |
Prestashop Prestashop | =8.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this PrestaShop cross-site scripting vulnerability is CVE-2023-39527.
CVE-2023-39527 has a severity rating of 8.3, which is considered high.
As a cybersecurity analyst, I cannot provide instructions on how to exploit vulnerabilities. It is important to prioritize security and report vulnerabilities to the developers.
To fix CVE-2023-39527 in PrestaShop version 1.7.8, update to version 1.7.8.10 or apply the available patch.
There are no known workarounds for CVE-2023-39527. It is important to update to the patched versions or apply the provided patches.