{"id":"CVE-2024-21627","aliases":["GHSA-xgpm-q3mq-46rq"],"url":"https://o3.security/vulnerability/CVE-2024-21627","summary":"Some attribute not escaped in Validate::isCleanHTML method","details":"### Description\nSome event attributes are not detected by the isCleanHTML method\n\n### Impact\nSome modules using the isCleanHTML method could be vulnerable to xss\n\n### Patches\n8.1.3, 1.7.8.11\n\n### Workarounds\nThe best workaround is to use the `HTMLPurifier` library to sanitize html input coming from users. The library is already available as a dependency in the PrestaShop project. Beware though that in legacy object models, fields of `HTML` type will call `isCleanHTML`.\n\n### Reporters\n\nReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub).\n\n","published":"2024-01-02T21:03:17.816Z","modified":"2026-08-12T03:51:24.936789887Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"prestashop/prestashop","fixedVersion":"8.1.3"},{"ecosystem":"Packagist","name":"prestashop/prestashop","fixedVersion":"1.7.8.11"}],"fix":{"url":"https://github.com/PrestaShop/PrestaShop/commit/73cfb44666818eefd501b526a894fe884dd12129","label":"PrestaShop/PrestaShop@73cfb44"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21627.json"},{"type":"ADVISORY","url":"https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-xgpm-q3mq-46rq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21627"},{"type":"FIX","url":"https://github.com/PrestaShop/PrestaShop/commit/73cfb44666818eefd501b526a894fe884dd12129"},{"type":"FIX","url":"https://github.com/PrestaShop/PrestaShop/commit/ba06d18466df5b92cb841d504cc7210121104883"},{"type":"WEB","url":"https://github.com/PrestaShop/PrestaShop/commit/0ed1af8de500538490f88e9e794e2e8113fb8df7"},{"type":"WEB","url":"https://github.com/PrestaShop/PrestaShop/commit/f799dcff564cd1b7ead932ffc3343b675107dbce"},{"type":"PACKAGE","url":"https://github.com/PrestaShop/PrestaShop"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:24.936789887Z"}}