CVE-2024-25841: Common-Services So Flexibilite
Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.
In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection.
Affected products
- Common-Services So Flexibilite: before 4.1.14 (fixed in 4.1.14)
Published 2024-02-27. Last modified 2026-06-17.