VDB
Sign up
HIGH8.0

GHSA-95hx-62rh-gg96

Potential XSS injection In PrestaShop contactform

Quick fix

GHSA-95hx-62rh-gg96 — prestashop/contactform: upgrade to the fixed version with the command below.

composer require prestashop/contactform:^4.3.0

Details

### Impact An attacker is able to inject javascript while using the contact form.

### Patches The problem is fixed in v4.3.0

### References [Cross-site Scripting (XSS) - Stored (CWE-79)](https://cwe.mitre.org/data/definitions/79.html)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/prestashop/contactform
Introduced in: 1.0.1Fixed in: 4.3.0
Fixcomposer require prestashop/contactform:^4.3.0

References