Show filters
121 Total Results
Displaying 31-40 of 121
Sort by:
Attacker Value
Unknown
CVE-2023-30192
Disclosure Date: May 12, 2023 (last updated October 08, 2023)
Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().
0
Attacker Value
Unknown
CVE-2023-30194
Disclosure Date: May 10, 2023 (last updated October 08, 2023)
Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().
0
Attacker Value
Unknown
CVE-2023-30282
Disclosure Date: May 04, 2023 (last updated October 08, 2023)
PrestaShop scexportcustomers <= 3.6.1 is vulnerable to Incorrect Access Control. Due to a lack of permissions' control, a guest can access exports from the module which can lead to leak of personal information from customer table.
0
Attacker Value
Unknown
CVE-2023-30839
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vulnerability. A BO user can write, update, and delete in the database, even without having specific rights. PrestaShop 8.0.4 and 1.7.8.9 contain a patch for this issue. There are no known workarounds.
0
Attacker Value
Unknown
CVE-2023-30838
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, the `ValidateCore::isCleanHTML()` method of Prestashop misses hijackable events which can lead to cross-site scripting (XSS) injection, allowed by the presence of pre-setup `@keyframes` methods. This XSS, which hijacks HTML attributes, can be triggered without any interaction by the visitor/administrator, which makes it as dangerous as a trivial XSS attack. Contrary to other attacks which target HTML attributes and are triggered without user interaction (such as onload / onerror which suffer from a very limited scope), this one can hijack every HTML element, which increases the danger due to a complete HTML elements scope. Versions 8.0.4 and 1.7.8.9 contain a fix for this issue.
0
Attacker Value
Unknown
CVE-2023-30545
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, it is possible for a user with access to the SQL Manager (Advanced Options -> Database) to arbitrarily read any file on the operating system when using SQL function `LOAD_FILE` in a `SELECT` request. This gives the user access to critical information. A patch is available in PrestaShop 8.0.4 and PS 1.7.8.9
0
Attacker Value
Unknown
CVE-2023-27570
Disclosure Date: March 21, 2023 (last updated October 08, 2023)
The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie.
0
Attacker Value
Unknown
CVE-2023-27569
Disclosure Date: March 21, 2023 (last updated October 08, 2023)
The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.
0
Attacker Value
Unknown
CVE-2023-25206
Disclosure Date: March 14, 2023 (last updated October 08, 2023)
PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection.
0
Attacker Value
Unknown
CVE-2023-25207
Disclosure Date: March 13, 2023 (last updated October 08, 2023)
PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.
0