Description
PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.
Remediation
References
Related Vulnerabilities
phpBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-7143)
WordPress Plugin WP Page Builder Multiple Vulnerabilities (1.2.3)
WordPress Plugin Geo Mashup Unspecified Vulnerability (1.10.3)
WordPress Plugin Gallery-Image and Video Gallery with Thumbnails SQL Injection (1.2.0)