VDB
Sign up
MEDIUM4.6

GHSA-vwfx-hh3w-fj99

Potential XSS injection in the newsletter conditions field

Quick fix

GHSA-vwfx-hh3w-fj99 — prestashop/ps_emailsubscription: upgrade to the fixed version with the command below.

composer require prestashop/ps_emailsubscription:^2.6.1

Details

### Impact An employee can inject javascript in the newsletter condition field that will then be executed on the front office

### Patches The issue has been fixed in 2.6.1

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/prestashop/ps_emailsubscription
Introduced in: 0Fixed in: 2.6.1
Fixcomposer require prestashop/ps_emailsubscription:^2.6.1

References