Description
In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and conditions) before executing the malicious link.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2012-1747 Vulnerability (CVE-2012-1747)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2200)
PHP 4.3.0 file disclosure and possible code execution
WordPress 4.8.x Multiple Vulnerabilities (4.8 - 4.8.13)
concrete5 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-11476)