VDB
Sign up
HIGH8.7

GHSA-58w4-w77w-qv3w

Reflected XSS with parameters in PostComment

Quick fix

GHSA-58w4-w77w-qv3w — prestashop/productcomments: upgrade to the fixed version with the command below.

composer require prestashop/productcomments:^4.2.0

Details

### Impact An attacker could inject malicious web code into the users' web browsers by creating a malicious link.

### Patches The problem is fixed in 4.2.0

### References [Cross-site Scripting (XSS) - Reflected (CWE-79) ](https://cwe.mitre.org/data/definitions/79.html)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/prestashop/productcomments
Introduced in: 4.0.0Fixed in: 4.2.0
Fixcomposer require prestashop/productcomments:^4.2.0

References