GHSA-prrh-qvhf-x788
Dashboard / Vulnerabilities / GHSA-prrh-qvhf-x788
Summary: PrestaShop Product Comments Cross-site Scripting vulnerability
Details: ### Impact An attacker could steal an admin's cookie ### Patches The issue is fixed in 5.0.2 ### References [Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')](https://cwe.mitre.org/data/definitions/79.html)
References: https://github.com/PrestaShop/productcomments/security/advisories/GHSA-prrh-qvhf-x788, https://nvd.nist.gov/vuln/detail/CVE-2022-35933, https://github.com/PrestaShop/productcomments/commit/314456d739155aa71f0b235827e8e0f24b97c26b, https://github.com/PrestaShop/productcomments
Affected packages
Package
Name: prestashop/productcomments
Purl: pkg:composer/prestashop/productcomments
Affected ranges
Type: ECOSYSTEM
Events:
