PrestaShop Socolissimo Module Multiple Cross Site Scripting Vulnerabilities
BID:52962
CVE-2012-6641 |Info
PrestaShop Socolissimo Module Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 52962 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-6641 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2012 12:00AM |
| Updated: | Apr 17 2014 01:02AM |
| Credit: | Arnault Pachot via Secunia |
| Vulnerable: |
PrestaShop PrestaShop 1.4.7.0 |
| Not Vulnerable: |
PrestaShop PrestaShop 1.4.7.2 |
Discussion
PrestaShop Socolissimo Module Multiple Cross Site Scripting Vulnerabilities
PrestaShop is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input in the Socolissimo module.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
PrestaShop 1.4.7.0 is vulnerable; prior versions may also be affected.
PrestaShop is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input in the Socolissimo module.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
PrestaShop 1.4.7.0 is vulnerable; prior versions may also be affected.
Exploit / POC
PrestaShop Socolissimo Module Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
PrestaShop Socolissimo Module Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
PrestaShop Socolissimo Module Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Changelog der Version 1.4.7.2 (PrestaShop)
- PrestaShop Homepage (PrestaShop)