Description
A cross-site scripting (XSS) vulnerability in PrestaShop v1.7.7.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the message parameter in /contactform/contactform.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP STAGING WordPress Backup-Migration Backup Restore Information Disclosure (3.4.3)
WordPress Plugin WP Page Builder Cross-Site Scripting (1.2.8)
WordPress Plugin WP Booking Calendar Multiple Vulnerabilities (3.0.0)
Apache read beyond bounds in mod_isapi Vulnerability (CVE-2022-28330)