Description
In PrestaShop from version 1.7.0.0 and before version 1.7.6.6, if a target sends a corrupted file, it leads to a reflected XSS. The problem is fixed in 1.7.6.6
Remediation
References
Related Vulnerabilities
WordPress Plugin All-in-One Event Calendar Cross-Site Scripting (2.4.0)
WordPress Plugin WP-Filebase Download Manager Remote Code Execution (0.3.0.03)
GlassFish CVE-2017-3247 Vulnerability (CVE-2017-3247)
WordPress Plugin VaultPress Unspecified Vulnerability (1.7.1)
Apache Tomcat Resource Management Errors Vulnerability (CVE-2011-0534)