Impact
In PrestaShop version 8.2.1, an insufficient validation of the Alias field in the address‑update process allows attackers to embed malicious expressions in user data. When a customer’s address is altered, these expressions persist in the database, and are later executed when the data is exported through the ‘Get my data in CSV’ tool. The result of such exploitation is the unauthorized disclosure of sensitive personal information.
Affected Systems
PrestaShop firmware version 8.2.1 is affected. No other versions are currently identified as at risk.
Risk and Exploitability
The likely attack vector is an attacker submitting a malicious Alias via the address‑update process, which is then executed when the data is exported to CSV. The CVSS score of 4.5 places the flaw in the moderate range, and the EPSS score of less than 1% indicates a low probability of exploitation at the moment. The vulnerability is not listed in CISA KEV. Because no vendor patch is available yet, the threat remains theoretical but should still be monitored, especially for customers who use the CSV export feature.
OpenCVE Enrichment