CVE-2022-45448 LOW

CVE-2022-45448: Cross-site Scripting in M4 PDF plugin for Prestashop sites

Vendor Prestashop
Product M4 PDF plugin
Weakness CWE-79 · XSS
Published September 20, 2023
Last update September 6, 2024

CVSS base score

3.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to an arbitrary HTML Document crafting vulnerability. The resource /m4pdf/pdf.php uses templates to dynamically create documents. In the case that the template does not exist, the application will return a fixed document with a message in mpdf format. An attacker could exploit this vulnerability by inputting a valid HTML/CSS document as the value of the parameter.

Key dates

02Disclosure timeline

September 20, 2023 CVE published
September 6, 2024 Record updated