An authenticated high-privilege user can bypass input validation on the customer private note field, allowing HTML/JavaScript injection (XSS). The fix adds a CleanHtml sanitization constraint to PrivateNoteType. Corrected patch for PrestaShop 1.7.6.x, where the prior patch referenced an undefined $this->translator property and caused HTTP 500.
This vulnerability affects the following application versions:
- PrestaShop 1.7.6.0
- PrestaShop 1.7.6.0 beta 1
- PrestaShop 1.7.6.0 RC 1
- PrestaShop 1.7.6.0 RC 2
- PrestaShop 1.7.6.0-beta.1
- PrestaShop 1.7.6.0-RC.1
- PrestaShop 1.7.6.0-RC.2
- PrestaShop 1.7.6.1
- PrestaShop 1.7.6.2
- PrestaShop 1.7.6.3
- PrestaShop 1.7.6.4
- PrestaShop 1.7.6.4 1
- PrestaShop 1.7.6.5
- PrestaShop 1.7.6.5 1
- PrestaShop 1.7.6.6
- PrestaShop 1.7.6.7
- PrestaShop 1.7.6.8
- PrestaShop 1.7.6.9
SOCIAL SHARE CARD GENERATOR