Description
In PrestaShop before version 1.7.6.5, there is a reflected XSS while running the security compromised page. It allows anyone to execute arbitrary action. The problem is patched in the 1.7.6.5.
Remediation
References
Related Vulnerabilities
Python Files or Directories Accessible to External Parties Vulnerability (CVE-2019-13404)
Coppermine Cross-site Scripting (XSS) Vulnerability (CVE-2018-14478)
WordPress Plugin Altos Connect Widget Cross-Site Scripting (1.3.0)
WordPress Plugin Dean's FCKEditor with pwwang's code Arbitrary File Upload (1.0.0)