PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.
DOWNLOAD: https://tinurli.com/2ev12z
DOWNLOAD: https://tinurli.com/2ev12z
CVE-2013-4791 (prestashop)
3925e8d270
Comments