CVE-2025-1230: Cross-Site Scripting (XSS) vulnerability in Prestashop
Stored Cross-Site Scripting (XSS) vulnerability in Prestashop 8.1.7, due to the lack of proper validation of user input through ‘/<admindirectory>/index.php’, affecting the ‘link’ parameter. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1230?
CVE-2025-1230 is classified as a High severity vulnerability due to its potential to allow stored cross-site scripting attacks.
How do I fix CVE-2025-1230?
To fix CVE-2025-1230, ensure proper validation and sanitization of user input in the affected parameters of Prestashop.
Which versions of Prestashop are affected by CVE-2025-1230?
CVE-2025-1230 affects Prestashop version 8.1.7 and possibly earlier versions that utilize the same input handling.
What are the potential impacts of exploiting CVE-2025-1230?
Exploiting CVE-2025-1230 can lead to unauthorized actions being performed on behalf of users, data exposure, and potentially compromising sensitive information.
Is there a patch available for CVE-2025-1230?
As of now, users are advised to monitor official channels for any patch or update releases that address CVE-2025-1230.