CVE-2024-25841: XSS
Published Feb 27, 2024
·Updated
In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection.
Affected Software
2 affected components
Prestashop Common-Services for PrestaShop<4.1.26
Common-Services So Flexibilite Prestashop<4.1.14
Event History
Feb 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25841?
CVE-2024-25841 is categorized as a high severity Cross Site Scripting (XSS) vulnerability affecting the So Flexibilite module.
2
How do I fix CVE-2024-25841?
To mitigate CVE-2024-25841, update the So Flexibilite module to version 4.1.26 or later.
3
Who is affected by CVE-2024-25841?
The vulnerability affects users of the So Flexibilite module in PrestaShop versions prior to 4.1.26.
4
Can CVE-2024-25841 be exploited remotely?
Yes, CVE-2024-25841 can be exploited remotely by authenticated customers through XSS injection.
5
What types of attacks can CVE-2024-25841 enable?
CVE-2024-25841 can enable attackers to execute malicious scripts in the context of the user's browser, potentially leading to data theft or session hijacking.