GHSA-prrh-qvhf-x788

Suggest an improvement
Source
https://github.com/advisories/GHSA-prrh-qvhf-x788
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-prrh-qvhf-x788/GHSA-prrh-qvhf-x788.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-prrh-qvhf-x788
Aliases
Published
2022-08-31T21:27:38Z
Modified
2023-11-01T04:59:23.970095Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
PrestaShop Product Comments Cross-site Scripting vulnerability
Details

Impact

An attacker could steal an admin's cookie

Patches

The issue is fixed in 5.0.2

References

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Database specific
{
    "nvd_published_at": "2022-09-02T20:15:00Z",
    "github_reviewed_at": "2022-08-31T21:27:38Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Packagist / prestashop/productcomments

Package

Name
prestashop/productcomments
Purl
pkg:composer/prestashop/productcomments

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.2

Affected versions

v3.*

v3.6.0
v3.6.1

v4.*

v4.0.0
v4.0.1
v4.1.0
v4.2.0
v4.2.2

4.*

4.2.1

v5.*

v5.0.0
v5.0.1