Description
In PrestaShop between versions 1.6.0.0 and 1.7.6.5, there is a reflected XSS with `date_from` and `date_to` parameters in the dashboard page This problem is fixed in 1.7.6.5
Remediation
References
Related Vulnerabilities
WordPress Plugin UpdraftPlus WordPress Backup Multiple Vulnerabilities (1.16.58)
WordPress Plugin VaultPress Remote Code Execution (1.9.0)
Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2024-25608)
WordPress Plugin Sagenda-Free booking system PHP Object Injection (1.3.2)