Description
In PrestaShop before version 1.7.6.5, there is a reflected XSS while running the security compromised page. It allows anyone to execute arbitrary action. The problem is patched in the 1.7.6.5.
Remediation
References
Related Vulnerabilities
WordPress Plugin BuddyDrive Cross-Site Scripting (1.2.2)
Apache HTTP Server Improper Encoding or Escaping of Output Vulnerability (CVE-2024-38474)
WordPress Plugin Dynamic Content for Elementor Remote Code Execution (1.9.5.6)
WordPress Plugin BezahlCode-Generator 'gen_name' Parameter Cross-Site Scripting (1.0)