MEDIUM4.3
GHSA-prrh-qvhf-x788
PrestaShop Product Comments Cross-site Scripting vulnerability
Quick fix
GHSA-prrh-qvhf-x788 — prestashop/productcomments: upgrade to the fixed version with the command below.
composer require prestashop/productcomments:^5.0.2Details
### Impact An attacker could steal an admin's cookie
### Patches The issue is fixed in 5.0.2
### References [Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')](https://cwe.mitre.org/data/definitions/79.html)
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/prestashop/productcomments
Introduced in:
0Fixed in: 5.0.2Fix
composer require prestashop/productcomments:^5.0.2