PrestaShop Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2013-4791 - Vulnerability Database
PrestaShop Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2013-4791
Medium
Reference:
CVE-2013-4791
Title:
PrestaShop Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
PrestaShop before 1.4.11 allows Logistician translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.