Impact Multiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates.
Patches Patched on 8.2.5 and 9.1.0
Workarounds None
References None
Impact A time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times.
Patches 8.2.4 and 9.0.3
Workarounds none
References Found by Lam Yiu Tung
Impact Fix improper use of validation framework
Patches Patched in 8.2.5 and 9.1.0
Workarounds None
References none