PrestaShop
cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*
- 8.2.1
A vulnerability exists in PrestaShop version 8.2.1 due to improper sanitization of elements, specifically in the 'Update your address' function. The issue arises from insufficient validation of the 'Alias' parameter, enabling attackers to inject malicious expressions. These expressions are executed when the 'Get my data in CSV' tool is used, potentially leading to unauthorized access to the victim's personal data.
Exploitation of this vulnerability could result in unauthorized access to personal data.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.