VulnerabilityModified
CVE-2021-21418
An employee can inject javascript in the newsletter condition field that will then be executed on the front office The issue has been fixed in 2.6.1
MEDIUM 5.4EPSS 0.79%
Does this matter?
Lower severity and a low EPSS score (0.79%). Track it; it rarely justifies an emergency change on its own.
Description
ps_emailsubscription is a newsletter subscription module for the PrestaShop platform. An employee can inject javascript in the newsletter condition field that will then be executed on the front office The issue has been fixed in 2.6.1
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.79% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- prestashop/ps emailsubscription
- Source
- security-advisories@github.com
References
- https://github.com/PrestaShop/ps_emailsubscription/commit/664ffb225e2afb4a32640bbedad667dc6e660b70Patch, Third Party Advisory
- https://github.com/PrestaShop/ps_emailsubscription/releases/tag/v2.6.1Release Notes, Third Party Advisory
- https://github.com/PrestaShop/ps_emailsubscription/security/advisories/GHSA-vwfx-hh3w-fj99Third Party Advisory
- https://packagist.org/packages/prestashop/ps_emailsubscriptionThird Party Advisory
- https://github.com/PrestaShop/ps_emailsubscription/commit/664ffb225e2afb4a32640bbedad667dc6e660b70Patch, Third Party Advisory
- https://github.com/PrestaShop/ps_emailsubscription/releases/tag/v2.6.1Release Notes, Third Party Advisory
- https://github.com/PrestaShop/ps_emailsubscription/security/advisories/GHSA-vwfx-hh3w-fj99Third Party Advisory
- https://packagist.org/packages/prestashop/ps_emailsubscriptionThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.