CVE-2023-39676
PrestaShop fieldpopupnewsletter Module - Cross Site Scripting
Record summary
CVE-2023-39676 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
FieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 26, 2024 · Source: CVE List
Nuclei templates
1ProjectDiscoveryMEDIUMPrestaShop fieldpopupnewsletter Module - Cross Site ScriptingCVSS 6.1
Fieldpopupnewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the affected website, leading to potential theft of sensitive information, session hijacking, or defacement.
Remediation
Apply the latest security patches and updates from the vendor to address this vulnerability.
Source: ProjectDiscovery