Description
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.7.3, an attacker can inject HTML when the Grid Column Type DataColumn is badly used. The problem is fixed in 1.7.7.3
Remediation
References
Related Vulnerabilities
WordPress Plugin Abandoned Cart Lite for WooCommerce SQL Injection (5.8.1)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5472)
WordPress Plugin Drag and Drop Multiple File Upload-Contact Form 7 Arbitrary File Upload (1.3.5.4)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2020-10969)