CVE-2025-24027
CVSS 3.1 Score 6.2 of 10 (medium)
Details
Summary
CVE-2025-24027 is a cross-site scripting (XSS) vulnerability affecting the ps_contactinfo module in PrestaShop versions up to 3.3.2. This issue cannot be exploited in fresh installs of PrestaShop, but shops with third-party modules vulnerable to SQL injections are at risk. For instance, an attacker could inject and execute a stored XSS script in formatting objects. The commit d60f9a5634b4fc2d3a8831fb08fe2e1f23cbfa39 prevents the display of XSS scripts stored in the database, and the expected fix is scheduled for version 3.3.3. No workarounds are available aside from applying the fix and keeping all modules updated.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.