M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to an arbitrary HTML Document crafting vulnerability. The resource /m4pdf/pdf.php uses templates to dynamically create documents. In the case that the template does not exist, the application will return a fixed document with a message in mpdf format. An attacker could exploit this vulnerability by inputting a valid HTML/CSS document as the value of the parameter.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: INCIBE
Published: 2023-09-20T12:14:58.361Z
Updated: 2024-09-06T14:11:51.047Z
Reserved: 2022-11-16T14:09:55.998Z
Link: CVE-2022-45448
Vulnrichment
Updated: 2024-08-03T14:17:00.905Z
NVD
Status : Modified
Published: 2023-09-20T13:15:11.180
Modified: 2024-11-21T07:29:16.430
Link: CVE-2022-45448
Redhat
No data.