PrestaShop SQL Injection and Cross Site Scripting Vulnerabilities
BID:67249
Info
PrestaShop SQL Injection and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 67249 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 05 2014 12:00AM |
| Updated: | May 05 2014 12:00AM |
| Credit: | Indoushka |
| Vulnerable: |
PrestaShop PrestaShop 1.6 |
| Not Vulnerable: | |
Discussion
PrestaShop SQL Injection and Cross Site Scripting Vulnerabilities
PrestaShop is prone to an SQL-injection vulnerability and a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database and to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
PrestaShop 1.6.0 is vulnerable; other versions may also be affected.
PrestaShop is prone to an SQL-injection vulnerability and a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database and to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
PrestaShop 1.6.0 is vulnerable; other versions may also be affected.
Solution / Fix
PrestaShop SQL Injection and Cross Site Scripting Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PrestaShop SQL Injection and Cross Site Scripting Vulnerabilities
References:
References:
- PrestaShop Homepage (PrestaShop)