Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1290 | PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, the `ValidateCore::isCleanHTML()` method of Prestashop misses hijackable events which can lead to cross-site scripting (XSS) injection, allowed by the presence of pre-setup `@keyframes` methods. This XSS, which hijacks HTML attributes, can be triggered without any interaction by the visitor/administrator, which makes it as dangerous as a trivial XSS attack. Contrary to other attacks which target HTML attributes and are triggered without user interaction (such as onload / onerror which suffer from a very limited scope), this one can hijack every HTML element, which increases the danger due to a complete HTML elements scope. Versions 8.0.4 and 1.7.8.9 contain a fix for this issue. |
Github GHSA |
GHSA-fh7r-996q-gvcp | Possible XSS injection through Validate::isCleanHTML method |
Mon, 03 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-03T19:34:54.511Z
Reserved: 2023-04-18T16:13:15.879Z
Link: CVE-2023-30838
Updated: 2024-08-02T14:37:15.536Z
Status : Modified
Published: 2023-04-25T19:15:11.160
Modified: 2024-11-21T08:00:56.743
Link: CVE-2023-30838
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA