PrestaShop module ps_facetedsearch versions before 3.5.0 has a reflected XSS with `url_name` parameter. The problem is fixed in 3.5.0
2020-03-25T19:15:15.840
2024-11-21T05:33:49.217
Modified
CVSSv3.1: 4.1 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | prestashop | faceted_search_module | < 3.5.0 | Yes |