CVE-2011-4544

Prestashop < 1.5 - Cross-Site Scripting via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2011-4544. PoCs published by Prestashop.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in PrestaShop's Mondial Relay module by injecting a malicious script via the 'num_mode' POST parameter. The vulnerability arises due to insufficient input sanitization, allowing arbitrary JavaScript execution in the context of the affected site.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Prestashop before 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) address or (2) relativ_base_dir parameter to modules/mondialrelay/googlemap.php; the (3) relativ_base_dir, (4) Pays, (5) Ville, (6) CP, (7) Poids, (8) Action, or (9) num parameter to prestashop/modules/mondialrelay/googlemap.php; (10) the num_mode parameter to modules/mondialrelay/kit_mondialrelay/RechercheDetailPointRelais_ajax.php; (11) the Expedition parameter to modules/mondialrelay/kit_mondialrelay/SuiviExpedition_ajax.php; or the (12) folder or (13) name parameter to admin/ajaxfilemanager/ajax_save_text.php.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Prestashop · textwebappsphp
https://www.exploit-db.com/exploits/36341

This exploit demonstrates a stored XSS vulnerability in PrestaShop's Mondial Relay module by injecting a malicious script via the 'num_mode' POST parameter. The vulnerability arises due to insufficient input sanitization, allowing arbitrary JavaScript execution in the context of the affected site.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: PrestaShop 1.4.4.1 (Mondial Relay module)
No auth needed
Prerequisites: Access to the target PrestaShop instance with the Mondial Relay module enabled
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Prestashop · textwebappsphp
https://www.exploit-db.com/exploits/36343

This exploit demonstrates a cross-site scripting (XSS) vulnerability in PrestaShop's Mondial Relay module. The vulnerability allows arbitrary script execution via unsanitized input in the 'Expedition' POST parameter.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: PrestaShop 1.4.4.1 (Mondial Relay module)
No auth needed
Prerequisites: Access to the target application's Mondial Relay module endpoint
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Prestashop · textwebappsphp
https://www.exploit-db.com/exploits/36342

This exploit demonstrates multiple XSS vulnerabilities in PrestaShop's mondialrelay module by injecting malicious JavaScript via unsanitized input parameters. The PoC provides direct URLs to trigger the vulnerabilities.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: PrestaShop 1.4.4.1
No auth needed
Prerequisites: Access to the target PrestaShop instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Prestashop · textwebappsphp
https://www.exploit-db.com/exploits/36344

This exploit demonstrates a stored XSS vulnerability in PrestaShop's ajax_save_text.php by injecting malicious scripts via the 'folder' and 'name' parameters. The vulnerability arises due to insufficient input sanitization, allowing arbitrary JavaScript execution in the context of the affected site.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: PrestaShop 1.4.4.1
Auth required
Prerequisites: Access to the admin panel · Valid session or authentication credentials
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/50784

Scores

EPSS 0.0331
EPSS Percentile 87.0%

Details

CWE
CWE-79
Status published
Products (21)
prestashop/prestashop 0.8.1
prestashop/prestashop 0.8.2
prestashop/prestashop 0.8.3
prestashop/prestashop 0.8.4
prestashop/prestashop 0.8.5
prestashop/prestashop 0.8.5.1
prestashop/prestashop 0.9
prestashop/prestashop 0.9.1 rc1 (2 CPE variants)
prestashop/prestashop 0.9.2
prestashop/prestashop 0.9.5
... and 11 more
Published Dec 01, 2011
Tracked Since Feb 18, 2026