PrestaShop Incorrect Sanitization Vulnerability in Address Update Function Allowing Data Injection

Vulnerability

A vulnerability exists in PrestaShop version 8.2.1 due to improper sanitization of elements, specifically in the 'Update your address' function. The issue arises from insufficient validation of the 'Alias' parameter, enabling attackers to inject malicious expressions. These expressions are executed when the 'Get my data in CSV' tool is used, potentially leading to unauthorized access to the victim's personal data.

Impact

Exploitation of this vulnerability could result in unauthorized access to personal data.

Added: Jul 13, 2026, 12:21 PM
Updated: Jul 13, 2026, 12:21 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
1.0
exploitability
5.0
remediation
0.0
relevance
9.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.