Filtered by vendor Common-services Subscriptions
Filtered by product So Flexibilite Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-25841 1 Common-services 1 So Flexibilite 2025-05-23 5.9 Medium
In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection.
CVE-2024-25844 1 Common-services 1 So Flexibilite 2025-05-23 7.5 High
An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate privileges and obtain sensitive information via debug file.