VDB
Sign up
MEDIUM4.3

GHSA-prrh-qvhf-x788

PrestaShop Product Comments Cross-site Scripting vulnerability

Quick fix

GHSA-prrh-qvhf-x788 — prestashop/productcomments: upgrade to the fixed version with the command below.

composer require prestashop/productcomments:^5.0.2

Details

### Impact An attacker could steal an admin's cookie

### Patches The issue is fixed in 5.0.2

### References [Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')](https://cwe.mitre.org/data/definitions/79.html)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/prestashop/productcomments
Introduced in: 0Fixed in: 5.0.2
Fixcomposer require prestashop/productcomments:^5.0.2

References