Description
PrestaShop before 1.5.2 allows XSS via the "<object data='data:text/html" substring in the message field.
Remediation
References
Related Vulnerabilities
WordPress 5.3.x Multiple Vulnerabilities (5.3 - 5.3.2)
Oracle HTTP Server Other Vulnerability (CVE-2020-35167)
Contao Improper Encoding or Escaping of Output Vulnerability (CVE-2019-19714)
Caddy Web Server Out-of-bounds Read Vulnerability (CVE-2022-34037)
WordPress Plugin Elementor Website Builder Unspecified Vulnerability (3.0.15)