{"id":"CVE-2019-11876","details":"In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and conditions) before executing the malicious link.","aliases":["GHSA-6grv-hw8g-4gfm"],"modified":"2026-08-07T15:00:03.991751Z","published":"2019-05-24T16:29:00.517Z","references":[{"type":"ADVISORY","url":"https://www.prestashop.com/forums/forum/2-prestashop-news-and-releases/"},{"type":"EVIDENCE","url":"https://www.logicallysecure.com/blog/xss-presta-xss-drupal/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/drupal/drupal","events":[{"introduced":"17ba30046ed57677de4feff8d07354890b40efdb"},{"last_affected":"17ba30046ed57677de4feff8d07354890b40efdb"}],"database_specific":{"extracted_events":[{"introduced":"8.7.0"},{"last_affected":"8.7.0"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:drupal:drupal:8.7.0:*:*:*:*:*:*:*"}}],"versions":["8.7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11876.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/prestashop/prestashop","events":[{"introduced":"4edececed3066f483a472d2ac9f611a7e800ad60"},{"last_affected":"4edececed3066f483a472d2ac9f611a7e800ad60"}],"database_specific":{"cpe":"cpe:2.3:a:prestashop:prestashop:1.7.5.2:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.7.5.2"},{"last_affected":"1.7.5.2"}],"source":"CPE_STRING"}}],"versions":["1.7.5.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11876.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}