M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to an arbitrary HTML Document crafting vulnerability. The resource /m4pdf/pdf.php uses templates to dynamically create documents. In the case that the template does not exist, the application will return a fixed document with a message in mpdf format. An attacker could exploit this vulnerability by inputting a valid HTML/CSS document as the value of the parameter.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2023-09-20T12:14:58.361Z

Updated: 2024-09-06T14:11:51.047Z

Reserved: 2022-11-16T14:09:55.998Z

Link: CVE-2022-45448

cve-icon Vulnrichment

Updated: 2024-08-03T14:17:00.905Z

cve-icon NVD

Status : Analyzed

Published: 2023-09-20T13:15:11.180

Modified: 2023-09-22T19:33:28.297

Link: CVE-2022-45448

cve-icon Redhat

No data.