Showing 1 vulnerability on this page for ps_contactinfo

Signals CISA KEV Ransomware Nuclei
PrestaShop vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

ps_contactinfo has potential XSS due to usage of the nofilter tag in template

ps_contactinfo, a PrestaShop module for displaying store contact information, has a cross-site scripting (XSS) vulnerability in versions up to and including 3.3.2. This can not be exploited in a fresh install of PrestaShop, only shops made vulnerable by third party modules are concerned. For example, if the shop has a third party module vulnerable to SQL injections, then ps_contactinfo might execute a stored cross-site scripting in formatting objects. Commit d60f9a5634b4fc2d3a8831fb08fe2e1f23cbf

CWE-79Jan 22, 2025
CVSS6.2v3.1EPSS0.403%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX