In PrestaShop contactform module (prestashop/contactform) before version 4.3.0, an attacker is able to inject JavaScript while using the contact form. The `message` field was incorrectly unescaped, possibly allowing attackers to execute arbitrary JavaScript in a victim's browser.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| prestashop/contactform(Packagist) | 1.0.1 | 4.3.0 | N/A |
CVSS Metrics