CVE-2021-21398

MEDIUM

PrestaShop 1.7.7.0-1.7.7.2 - Cross-Site Scripting via Grid Column Type DataColumn

Title source: llm
STIX 2.1

Description

PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.7.3, an attacker can inject HTML when the Grid Column Type DataColumn is badly used. The problem is fixed in 1.7.7.3

Scores

CVSS v3 5.4
EPSS 0.0070
EPSS Percentile 48.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
prestashop/prestashop 1.7.7.0 - 1.7.7.3
Published Mar 30, 2021
Tracked Since Feb 18, 2026