We found results for “”
CVE-2025-1230
Good to know:
Date: February 12, 2025
Stored Cross-Site Scripting (XSS) vulnerability in Prestashop 8.1.7, due to the lack of proper validation of user input through ‘/<admin_directory>/index.php’, affecting the ‘link’ parameter. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.
Severity Score
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix
Upgrade Version
Upgrade to version prestashop/prestashop - dev-8.0.0-rc;prestashop/prestashop - dev-release/1.7.8.10;prestashop/prestashop - dev-dependabot/npm_and_yarn/tests/UI/develop/jsdoc-to-markdown-8.0.3;prestashop/prestashop - dev-8.0.0-rc1;prestashop/prestashop - dev-1.7.8.7-release;prestashop/prestashop - dev-8.1.x-backup;prestashop/prestashop - dev-1.7.8.0-build;prestashop/prestashop - dev-8.1.0-build1;prestashop/prestashop - dev-1.7.8.x-8.0.x;prestashop/prestashop - dev-1.7.8.2-build;prestashop/prestashop - 8.2.0;prestashop/prestashop - dev-1.7.8.4-build;prestashop/prestashop - dev-dependabot/npm_and_yarn/tests/UI/develop/faker-js/faker-8.0.2;prestashop/prestashop - dev-build-1-8.1.3;prestashop/prestashop - dev-8.1.4-build;prestashop/prestashop - dev-dependabot/npm_and_yarn/tests/UI/develop/faker-js/faker-8.0.1;prestashop/prestashop - dev-dependabot/npm_and_yarn/tests/UI/develop/eslint-plugin-html-8.1.1;prestashop/prestashop - dev-dependabot/npm_and_yarn/tests/UI/develop/eslint-plugin-html-8.1.2;prestashop/prestashop - dev-cron-php-update-modules-8.0.x
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | HIGH |
| User Interaction (UI): | REQUIRED |
| Scope (S): | CHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | LOW |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


