Description
PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.
Remediation
References
Related Vulnerabilities
WordPress 5.3.x Multiple Vulnerabilities (5.3 - 5.3.16)
WordPress Improper Input Validation Vulnerability (CVE-2020-35539)
WordPress 5.2.x Multiple Vulnerabilities (5.2 - 5.2.3)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1429)
Joomla Improper Input Validation Vulnerability (CVE-2006-4468)