Impact Multiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates.
Patches Patched on 8.2.5 and 9.1.0
Workarounds None
References None
Impact Fix improper use of validation framework
Patches Patched in 8.2.5 and 9.1.0
Workarounds None
References none
Impact A time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times.
Patches 8.2.4 and 9.0.3
Workarounds none
References Found by Lam Yiu Tung