Potential XSS injection In PrestaShop contactform
High severity
GitHub Reviewed
Published
Sep 15, 2020
in
PrestaShop/contactform
•
Updated Jan 12, 2023
Package
Affected versions
>= 1.0.1, < 4.3.0
Patched versions
4.3.0
Description
Reviewed
Sep 15, 2020
Published to the GitHub Advisory Database
Sep 15, 2020
Last updated
Jan 12, 2023
Impact
An attacker is able to inject javascript while using the contact form.
Patches
The problem is fixed in v4.3.0
References
Cross-site Scripting (XSS) - Stored (CWE-79)
References