Vulnerability Description
FieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fieldthemes | Fieldpopupnewsletter | 1.0.0 |
Related Weaknesses (CWE)
References
- https://blog.sorcery.ie/posts/fieldpopupnewsletter_xss/Exploit
- https://sorcery.ieNot Applicable
- https://themeforest.net/user/fieldthemesProduct
- https://blog.sorcery.ie/posts/fieldpopupnewsletter_xss/Exploit
- https://sorcery.ieNot Applicable
- https://themeforest.net/user/fieldthemesProduct
FAQ
What is CVE-2023-39676?
CVE-2023-39676 is a vulnerability with a CVSS score of 6.1 (MEDIUM). FieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php.
How severe is CVE-2023-39676?
CVE-2023-39676 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-39676?
Check the references section above for vendor advisories and patch information. Affected products include: Fieldthemes Fieldpopupnewsletter.