.. / CVE-2023-39676

Exploit for PrestaShop fieldpopupnewsletter Module - Cross Site Scripting (CVE-2023-39676)

Description:

Fieldpopupnewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php.

Nuclei Template

View the template here CVE-2023-39676.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2023/CVE-2023-39676.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2023-39676
https://blog.sorcery.ie/posts/fieldpopupnewsletter_xss/
https://themeforest.net/user/fieldthemes
https://sorcery.ie