Description
In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/default/template/header.tpl, and themes/new-theme/js/header.js.
Remediation
References
Related Vulnerabilities
WordPress 4.0.x Multiple Vulnerabilities (4.0 - 4.0.12)
MySQL CVE-2022-21297 Vulnerability (CVE-2022-21297)
IBM RTC Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2020-4547)
Oracle HTTP Server Other Vulnerability (CVE-2006-5349)
WordPress Plugin WP Google Fonts Cross-Site Scripting (3.1.3)