Show filters
95 Total Results
Displaying 11-20 of 95
Sort by:
Attacker Value
Unknown

CVE-2023-43663

Disclosure Date: September 28, 2023 (last updated October 08, 2023)
PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit `ce1f6708` addresses this issue and is included in version 8.1.2. Users are advised to upgrade. There are no known workarounds for this issue.
Attacker Value
Unknown

CVE-2023-39530

Disclosure Date: August 07, 2023 (last updated October 08, 2023)
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete files from the server via the CustomerMessage API. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
Attacker Value
Unknown

CVE-2023-39529

Disclosure Date: August 07, 2023 (last updated October 08, 2023)
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete a file from the server by using the Attachments controller and the Attachments API. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
Attacker Value
Unknown

CVE-2023-39528

Disclosure Date: August 07, 2023 (last updated October 08, 2023)
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, the `displayAjaxEmailHTML` method can be used to read any file on the server, potentially even outside of the project if the server is not correctly configured. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
Attacker Value
Unknown

CVE-2023-39527

Disclosure Date: August 07, 2023 (last updated October 08, 2023)
PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to cross-site scripting through the `isCleanHTML` method. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.
Attacker Value
Unknown

CVE-2023-39526

Disclosure Date: August 07, 2023 (last updated October 08, 2023)
PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through SQL injection and arbitrary file write in the back office. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.
Attacker Value
Unknown

CVE-2023-39525

Disclosure Date: August 07, 2023 (last updated October 08, 2023)
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, in the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path that uses the traversal path. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
Attacker Value
Unknown

CVE-2023-39524

Disclosure Date: August 07, 2023 (last updated October 08, 2023)
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, SQL injection possible in the product search field, in BO's product page. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
Attacker Value
Unknown

CVE-2023-30151

Disclosure Date: July 13, 2023 (last updated October 08, 2023)
A SQL injection vulnerability in the Boxtal (envoimoinscher) module for PrestaShop, after version 3.1.10, allows remote attackers to execute arbitrary SQL commands via the `key` GET parameter.
Attacker Value
Unknown

CVE-2023-31672

Disclosure Date: June 15, 2023 (last updated October 08, 2023)
In the PrestaShop < 2.4.3 module "Length, weight or volume sell" (ailinear) there is a SQL injection vulnerability.