Medium severity5.4NVD Advisory· Published Feb 14, 2020· Updated Jun 16, 2026
CVE-2013-4791
CVE-2013-4791
Description
PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
prestashop/prestashopPackagist | < 1.4.11 | 1.4.11 |
Affected products
3- PrestaShop/PrestaShopdescription
Patches
Vulnerability mechanics
References
3- davidsopaslabs.blogspot.com/2013/07/prestashop-persistent-xss-and-csrf.htmlnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-crpg-2mm2-jjqfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2013-4791ghsaADVISORY
News mentions
0No linked articles in our index yet.