Description
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed in 1.7.7.2
Remediation
References
Related Vulnerabilities
Oracle Application Server CVE-2006-5363 Vulnerability (CVE-2006-5363)
phpMyAdmin Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-5159)
WordPress Plugin Mang Board WP Unspecified Vulnerability (2.0.5)
WordPress Plugin Contact Form 7 Datepicker Cross-Site Scripting (2.6.0)
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2019-16335)