PrestaShop
cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*
- < 8.2.5
- < 9.1.0
A stored cross-site scripting vulnerability has been identified in PrestaShop versions prior to 8.2.5 and 9.1.0. This vulnerability allows an attacker with limited back-office access or knowledge of a pre-existing vulnerability to inject data into the database. The injected data can then be exploited by manipulating unprotected variables in back-office templates.
Exploitation of this vulnerability allows for multiple stored cross-site scripting issues in the back office, where injected scripts are executed in the context of the user.
Users can upgrade to PrestaShop versions 8.2.5 or 9.1.0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.