Medium severity5.9NVD Advisory· Published Feb 27, 2024· Updated Jun 17, 2026
CVE-2024-25841
CVE-2024-25841
Description
In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:common-services:so_flexibilite:*:*:*:*:*:prestashop:*:*Range: <4.1.14
- Common-Services for PrestaShop/So Flexibilitedescription
- Range: <4.1.26
Patches
Vulnerability mechanics
References
2- security.friendsofpresta.org/modules/2024/02/27/soflexibilite.htmlnvdExploitThird Party Advisory
- addons.prestashop.com/fr/transporteurs/2704-colissimo-domicile-et-points-de-retrait.htmlnvdProduct
News mentions
0No linked articles in our index yet.