CSV Injection in PrestaShop - CVE-2021-21302
Published: February 22, 2021
PrestaShop
PrestaShop SA
Description
The vulnerability allows a remote attacker to inject arbitrary content via CSV files.
The vulnerability exists due to improper input validation in shop search keywords via the admin panel when processing CSV files. A remote attacker can trick the victim to load a specially crafted CVS file and inject arbitrary content to the website.