Description
In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/default/template/header.tpl, and themes/new-theme/js/header.js.
Remediation
References
Related Vulnerabilities
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-7859)
PHP Improper Restriction of XML External Entity Reference Vulnerability (CVE-2013-1824)
MySQL CVE-2019-2800 Vulnerability (CVE-2019-2800)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-3062)