Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown

CVE-2023-26858

Disclosure Date: March 31, 2023 (last updated October 08, 2023)
SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqsBudgetModuleFrontController::displayAjaxGenerateBudget component.
Attacker Value
Unknown

CVE-2021-40814

Disclosure Date: September 08, 2021 (last updated February 23, 2025)
The Customer Photo Gallery addon before 2.9.4 for PrestaShop is vulnerable to SQL injection.
Attacker Value
Unknown

CVE-2018-19355

Disclosure Date: November 19, 2018 (last updated November 27, 2024)
modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a php file via modules/orderfiles/upload.php with auptype equal to product (for upload destinations under modules/productfiles), order (for upload destinations under modules/files), or cart (for upload destinations under modules/cartfiles).