MEDIUM4.6
GHSA-vwfx-hh3w-fj99
Potential XSS injection in the newsletter conditions field
Quick fix
GHSA-vwfx-hh3w-fj99 — prestashop/ps_emailsubscription: upgrade to the fixed version with the command below.
composer require prestashop/ps_emailsubscription:^2.6.1Details
### Impact An employee can inject javascript in the newsletter condition field that will then be executed on the front office
### Patches The issue has been fixed in 2.6.1
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/prestashop/ps_emailsubscription
Introduced in:
0Fixed in: 2.6.1Fix
composer require prestashop/ps_emailsubscription:^2.6.1References
- https://github.com/PrestaShop/ps_emailsubscription/security/advisories/GHSA-vwfx-hh3w-fj99[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-21418[ADVISORY]
- https://github.com/PrestaShop/ps_emailsubscription/commit/664ffb225e2afb4a32640bbedad667dc6e660b70[WEB]
- https://github.com/PrestaShop/ps_emailsubscription/releases/tag/v2.6.1[WEB]
- https://packagist.org/packages/prestashop/ps_emailsubscription[WEB]