Potential XSS injection in the newsletter conditions field
Moderate severity
GitHub Reviewed
Published
Mar 31, 2021
in
PrestaShop/ps_emailsubscription
•
Updated Feb 1, 2023
Description
Reviewed
Mar 31, 2021
Published by the National Vulnerability Database
Mar 31, 2021
Published to the GitHub Advisory Database
Apr 6, 2021
Last updated
Feb 1, 2023
Impact
An employee can inject javascript in the newsletter condition field that will then be executed on the front office
Patches
The issue has been fixed in 2.6.1
References