Description
PrestaShop before 1.5.2 allows XSS via the "<object data='data:text/html" substring in the message field.
Remediation
References
Related Vulnerabilities
WordPress Plugin WPML (WordPress Multilingual) Cross-Site Scripting (3.2.6)
WordPress Plugin WP eCommerce 'collected_data[]' SQL Injection (3.8.4)
WordPress Plugin URL Cloak & Encrypt Cross-Site Scripting (2.0)
WordPress Plugin Simplr Registration Form Plus+ Privilege Escalation (2.4.3)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-0738)