CVE-2021-21398

MEDIUM

Prestashop < 1.7.7.3 - XSS

Title source: rule
STIX 2.1

Description

PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.7.3, an attacker can inject HTML when the Grid Column Type DataColumn is badly used. The problem is fixed in 1.7.7.3

Scores

CVSS v3 5.4
EPSS 0.0026
EPSS Percentile 49.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
prestashop/prestashop 1.7.7.0 - 1.7.7.3
Published Mar 30, 2021
Tracked Since Feb 18, 2026