icon

We found results for “

CVE-2025-1230

Good to know:

icon

Date: February 12, 2025

Stored Cross-Site Scripting (XSS) vulnerability in Prestashop 8.1.7, due to the lack of proper validation of user input through ‘/<admin_directory>/index.php’, affecting the ‘link’ parameter. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version prestashop/prestashop - dev-8.0.0-rc;prestashop/prestashop - dev-release/1.7.8.10;prestashop/prestashop - dev-dependabot/npm_and_yarn/tests/UI/develop/jsdoc-to-markdown-8.0.3;prestashop/prestashop - dev-8.0.0-rc1;prestashop/prestashop - dev-1.7.8.7-release;prestashop/prestashop - dev-8.1.x-backup;prestashop/prestashop - dev-1.7.8.0-build;prestashop/prestashop - dev-8.1.0-build1;prestashop/prestashop - dev-1.7.8.x-8.0.x;prestashop/prestashop - dev-1.7.8.2-build;prestashop/prestashop - 8.2.0;prestashop/prestashop - dev-1.7.8.4-build;prestashop/prestashop - dev-dependabot/npm_and_yarn/tests/UI/develop/faker-js/faker-8.0.2;prestashop/prestashop - dev-build-1-8.1.3;prestashop/prestashop - dev-8.1.4-build;prestashop/prestashop - dev-dependabot/npm_and_yarn/tests/UI/develop/faker-js/faker-8.0.1;prestashop/prestashop - dev-dependabot/npm_and_yarn/tests/UI/develop/eslint-plugin-html-8.1.1;prestashop/prestashop - dev-dependabot/npm_and_yarn/tests/UI/develop/eslint-plugin-html-8.1.2;prestashop/prestashop - dev-cron-php-update-modules-8.0.x

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): HIGH
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us