CVE-2024-21628: XSS can be stored in DB from "add a message form" in order detail page (FO)

Published Jan 2, 2024
·
Updated

Impact The isCleanHtml method is not used on this this form, which makes it possible to store an xss in DB. The impact is low because the html is not interpreted in BO, thanks to twig's escape mechanism. In FO, the xss is effective, but only impacts the customer sending it, or the customer session from which it was sent.

Be careful if you have a module fetching these messages from the DB and displaying it without escaping html.

Patches 8.1.x

Reporter Reported by Rona Febriana (linkedin: https://www.linkedin.com/in/rona-febriana/)

Other sources

PrestaShop is an open-source e-commerce platform. Prior to version 8.1.3, the isCleanHtml method is not used on this this form, which makes it possible to store a cross-site scripting payload in the database. The impact is low because the HTML is not interpreted in BO, thanks to twig's escape mechanism. In FO, the cross-site scripting attack is effective, but only impacts the customer sending it, or the customer session from which it was sent. This issue affects those who have a module fetching these messages from the DB and displaying it without escaping HTML. Version 8.1.3 contains a patch for this issue.

Affected Software

2 affected componentsFixes available
composer/prestashop/prestashop<8.1.3
8.1.3
Prestashop PrestaShop<8.1.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/prestashop/prestashop to a version that resolves this vulnerability.

    Fixed in 8.1.3
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 8.1.3
  3. Configuration

    If you have a module that fetches messages from the database and displays them in Front-Office, ensure the message content is escaped before rendering in HTML to prevent XSS (this is a concern where messages are displayed without escaping HTML).

    Module fetching messages for display (PrestaShop FO) HTML escaping = escape output (use escaping)

Event History

Jan 2, 2024
CVE Published
09:17 PM
Data Sourced
09:17 PM
DescriptionSeverityWeakness
Jan 3, 2024
Advisory Published
09:48 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-21628?

The severity of CVE-2024-21628 is considered low due to the HTML being escaped by Twig's mechanism.

2

How do I fix CVE-2024-21628?

To fix CVE-2024-21628, upgrade to a version of PrestaShop that is beyond 8.1.3.

3

What systems are affected by CVE-2024-21628?

CVE-2024-21628 affects PrestaShop versions up to and including 8.1.3.

4

What type of vulnerability is CVE-2024-21628?

CVE-2024-21628 is an XSS (Cross-Site Scripting) vulnerability that could allow for potential data exposure.

5

Can CVE-2024-21628 be exploited in the back office?

No, CVE-2024-21628 cannot be exploited in the back office because HTML is not interpreted due to Twig's escape mechanism.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203