CVE-2021-21418

    Dashboard / Vulnerabilities / CVE-2021-21418

    CVE-2021-21418

    Published: 31 Mar 2021Last Modified: 9 Jul 2026

    Summary:

    Details: ps_emailsubscription is a newsletter subscription module for the PrestaShop platform. An employee can inject javascript in the newsletter condition field that will then be executed on the front office The issue has been fixed in 2.6.1

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- d4ef6d74fe3dd3f2f3a0cd7c7c6b92bf0f9277f6

    Affected versions

    v2.6.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2021-21418 | CVE-DB