Description
In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feature` parameter. The problem is fixed in 1.7.6.5
Remediation
References
Related Vulnerabilities
Jenkins Insufficient Session Expiration Vulnerability (CVE-2019-1003004)
MongoDb Excessive Iteration Vulnerability (CVE-2018-20805)
WordPress Plugin Craw Data Server-Side Request Forgery (1.0.0)
WordPress Plugin DM Albums 'album.php' Remote File Inclusion (1.9.2)
WordPress Plugin Calendar Event Multi View Multiple Vulnerabilities (1.1.4)