{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/prestashop/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PrestaShop"],"_cs_severities":["high"],"_cs_tags":["prestashop","xss","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["PrestaShop"],"content_html":"\u003cp\u003eMultiple stored Cross-Site Scripting (XSS) vulnerabilities have been identified in PrestaShop versions prior to 8.2.5 and in versions 9.0.0-alpha.1 to 9.1.0. These vulnerabilities allow an attacker who has the ability to inject data into the database, either through limited back-office access or by exploiting a pre-existing vulnerability, to execute arbitrary JavaScript code in the context of a back-office user's browser. This is achieved by exploiting unprotected variables in back-office templates. Successful exploitation could lead to account takeover, data theft, or further compromise of the PrestaShop installation. The vulnerability is identified as CVE-2026-33673. Patches are available in versions 8.2.5 and 9.1.0.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Compromise:\u003c/strong\u003e The attacker gains unauthorized access to the PrestaShop back office, either through brute-force attacks, credential stuffing, or exploitation of other vulnerabilities (e.g., SQL injection, authentication bypass).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDatabase Injection:\u003c/strong\u003e The attacker injects malicious JavaScript code into a database field that is later rendered in a back-office template. This can be achieved by manipulating input fields or directly modifying database records if sufficient privileges are obtained.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eTemplate Rendering:\u003c/strong\u003e A back-office user accesses a page that renders the template containing the injected malicious code.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eXSS Execution:\u003c/strong\u003e The injected JavaScript code executes within the user's browser session due to the lack of proper output escaping or sanitization in the template.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eSession Hijacking/Account Takeover:\u003c/strong\u003e The attacker's JavaScript code steals the user's session cookies or other authentication tokens.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePrivilege Escalation:\u003c/strong\u003e Using the stolen session, the attacker gains access to the back-office user's account, potentially with administrative privileges.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFurther Exploitation:\u003c/strong\u003e The attacker uses the compromised account to modify store settings, install malicious modules, steal sensitive data (customer information, financial data), or deface the website.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePersistence:\u003c/strong\u003e The attacker establishes persistent access by creating rogue administrator accounts or installing backdoors within the PrestaShop system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these XSS vulnerabilities can have severe consequences for PrestaShop store owners and their customers. An attacker can gain full control of the store's back office, leading to unauthorized access to sensitive data, including customer information and financial details. This can result in financial losses, reputational damage, and legal liabilities for the store owner. While specific victim counts are unavailable, the widespread use of PrestaShop makes this a potentially high-impact vulnerability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade PrestaShop installations to version 8.2.5 or 9.1.0 to patch CVE-2026-33673.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation and output encoding on all user-supplied data to prevent XSS attacks.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious activity, such as unusual requests to back-office pages or attempts to inject malicious code into database fields (see example Sigma rule).\u003c/li\u003e\n\u003cli\u003eEnforce strong password policies and multi-factor authentication for all back-office user accounts.\u003c/li\u003e\n\u003cli\u003eRegularly audit PrestaShop installations for security vulnerabilities and apply security patches promptly.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2024-01-03T12:00:00Z","date_published":"2024-01-03T12:00:00Z","id":"https://feed.craftedsignal.io/briefs/2024-01-03-prestashop-xss/","summary":"Multiple stored XSS vulnerabilities exist in PrestaShop, where an attacker with database access can exploit unprotected variables in back-office templates to execute malicious scripts in a user's browser.","title":"PrestaShop Stored XSS Vulnerability via Unprotected Template Variables","url":"https://feed.craftedsignal.io/briefs/2024-01-03-prestashop-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - PrestaShop","version":"https://jsonfeed.org/version/1.1"}