OSV 1.4.0 · github-reviewed · 修改于 2026-05-09 00:54
发布时间
2026-05-09 00:54
GitHub 审查时间
2026-05-09 00:54
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/05/GHSA-w9f3-qc75-qgx9/GHSA-w9f3-qc75-qgx9.json
This is a stored Cross-site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view.
An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover.
Patched in PrestaShop 8.2.6 and 9.1.1.
None.
[email protected]) in collaboration with Anthropic Research.