PrestaShop
cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*
- 8.1.7
A stored cross-site scripting vulnerability has been identified in PrestaShop version 8.1.7. This issue arises from inadequate validation of user input in the 'link' parameter on the admin index page. As a result, a remote user could craft a query that, when accessed by an authenticated user, would steal their session cookie.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
Users are advised to update to the latest version of PrestaShop. The manufacturer is currently working on a fix for this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.