PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2023-08-28T23:31:44Z",
"nvd_published_at": "2020-02-14T00:15:00Z",
"severity": "MODERATE"
}