In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feature` parameter. The problem is fixed in 1.7.6.5
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 44.5%