GHSA-fh7r-996q-gvcp

    Dashboard / Vulnerabilities / GHSA-fh7r-996q-gvcp

    GHSA-fh7r-996q-gvcp

    Published: 25 Apr 2023Last Modified: 16 Jul 2026

    Summary: Possible XSS injection through Validate::isCleanHTML method

    Details: ### Impact ValidateCore::isCleanHTML() method of Prestashop misses hijickable events which can lead to XSS injection, allowed by the presence of pre-setup @keyframes methods. This XSS which hijacks HTML attributes will be triggered without any interaction of the visitor/administrator which makes it as dangerous as a trivial XSS. Contrary to most XSS which target HTML attributes and which are triggered without user interaction (such as onload / onerror which suffer from a very limited scope), this one can hijack every HTML element, which increases the danger due to a complete HTML elements scope. ### Patches The patch will be on PS 8.0.4 and PS 1.7.8.9 ### References

    Affected packages

    Package

    Name: prestashop/prestashop

    Purl: pkg:composer/prestashop/prestashop

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 8.0.0
    Fixed -8.0.4

    Affected versions

    8.0.0
    8.0.1
    8.0.2
    8.0.3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-fh7r-996q-gvcp | CVE-DB