Description
In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/default/template/header.tpl, and themes/new-theme/js/header.js.
Remediation
References
Related Vulnerabilities
Apache HTTP Server Improper Handling of Case Sensitivity Vulnerability (CVE-2001-0766)
Lighttpd Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-1111)
WordPress Plugin Add-on SweetAlert Contact Form 7 Unspecified Vulnerability (1.0.7)
Oracle Database Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-5499)
Envoy Proxy Excessive Iteration Vulnerability (CVE-2021-32778)