Description
In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feature` parameter. The problem is fixed in 1.7.6.5
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Support Plus Responsive Ticket System Unspecified Vulnerability (8.0.7)
Atlassian Jira Incorrect Authorization Vulnerability (CVE-2021-43948)
WordPress Plugin Child Theme Configurator Arbitrary File Disclosure (1.7.4)
WordPress Plugin AccessPress Social Icons SQL Injection (1.8.0)