CVE-2021-21418
MEDIUMPrestaShop ps_emailsubscription < 2.6.1 - Stored Cross-Site Scripting in Newsletter Condition Field
Title source: llmDescription
ps_emailsubscription is a newsletter subscription module for the PrestaShop platform. An employee can inject javascript in the newsletter condition field that will then be executed on the front office The issue has been fixed in 2.6.1
References (4)
Core 4
Core References
Third Party Advisory x_refsource_confirm
https://github.com/PrestaShop/ps_emailsubscription/security/advisories/GHSA-vwfx-hh3w-fj99
Patch, Third Party Advisory x_refsource_misc
https://github.com/PrestaShop/ps_emailsubscription/commit/664ffb225e2afb4a32640bbedad667dc6e660b70
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/PrestaShop/ps_emailsubscription/releases/tag/v2.6.1
Third Party Advisory x_refsource_misc
https://packagist.org/packages/prestashop/ps_emailsubscription
Scores
CVSS v3
4.6
EPSS
0.0079
EPSS Percentile
51.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
prestashop/ps_emailsubscription
0 - 2.6.1Packagist
prestashop/ps_emailsubscription
2.6.0 - 2.6.1
Published
Mar 31, 2021
Tracked Since
Feb 18, 2026