PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.7.3, an attacker can inject HTML when the Grid Column Type DataColumn is badly used. The problem is fixed in 1.7.7.3
{ "extracted_events": [ { "introduced": "1.7.7.0" }, { "fixed": "1.7.7.3" } ], "source": [ "CPE_RANGE", "REFERENCES" ], "cpe": "cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*" }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-21398.json"