CVE-2024-25841
PoC —CVSS 3.1
5.9 medium
EPSS
<1%p32
Published
()
Modified
Description
In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection.
- Vendors
- common-services
- Products
- so flexibilite
- Ecosystems
- E-commerce
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.