Description
In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is a reflected XSS on Search page with `alias` and `search` parameters. The problem is patched in 1.7.6.5
Remediation
References
Related Vulnerabilities
WordPress Plugin Spotlight Social Feeds [Block, Shortcode, and Widget] Security Bypass (0.10.1)
WordPress Plugin Related Sites 'guid' Parameter SQL Injection (2.1)
Moment.js Uncontrolled Resource Consumption Vulnerability (CVE-2016-4055)
Oracle Database Server CVE-2019-2516 Vulnerability (CVE-2019-2516)