Description
In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feature` parameter. The problem is fixed in 1.7.6.5
Remediation
References
Related Vulnerabilities
WordPress Plugin Fast Velocity Minify Information Disclosure (2.7.6)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6102)
TYPO3 Improper Authentication Vulnerability (CVE-2009-0256)
WebLogic CVE-2019-2618 Vulnerability (CVE-2019-2618)
WordPress Improper Authentication Vulnerability (CVE-2008-1930)