Show filters
95 Total Results
Displaying 71-80 of 95
Sort by:
Attacker Value
Unknown

CVE-2019-19595

Disclosure Date: December 05, 2019 (last updated November 27, 2024)
reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers to execute arbitrary code by uploading a .php file.
Attacker Value
Unknown

CVE-2019-19594

Disclosure Date: December 05, 2019 (last updated November 27, 2024)
reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute arbitrary code by uploading a .php file.
Attacker Value
Unknown

CVE-2019-13461

Disclosure Date: July 09, 2019 (last updated November 27, 2024)
In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure Direct Object Reference vulnerability due to a guessable value sent to the web application during checkout. An attacker could leak personal customer information. This is PrestaShop bug #14444.
0
Attacker Value
Unknown

CVE-2019-11876

Disclosure Date: May 24, 2019 (last updated November 27, 2024)
In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and conditions) before executing the malicious link.
0
Attacker Value
Unknown

CVE-2018-20717

Disclosure Date: January 15, 2019 (last updated November 27, 2024)
In the orders section of PrestaShop before 1.7.2.5, an attack is possible after gaining access to a target store with a user role with the rights of at least a Salesman or higher privileges. The attacker can then inject arbitrary PHP objects into the process and abuse an object chain in order to gain Remote Code Execution. This occurs because protection against serialized objects looks for a 0: followed by an integer, but does not consider 0:+ followed by an integer.
0
Attacker Value
Unknown

CVE-2018-19355

Disclosure Date: November 19, 2018 (last updated November 27, 2024)
modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a php file via modules/orderfiles/upload.php with auptype equal to product (for upload destinations under modules/productfiles), order (for upload destinations under modules/files), or cart (for upload destinations under modules/cartfiles).
Attacker Value
Unknown

CVE-2018-19124

Disclosure Date: November 09, 2018 (last updated November 27, 2024)
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 on Windows allows remote attackers to write to arbitrary image files.
0
Attacker Value
Unknown

CVE-2018-19125

Disclosure Date: November 09, 2018 (last updated November 27, 2024)
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to delete an image directory.
0
Attacker Value
Unknown

CVE-2018-19126

Disclosure Date: November 09, 2018 (last updated November 27, 2024)
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload.
0
Attacker Value
Unknown

CVE-2018-13784

Disclosure Date: July 09, 2018 (last updated November 27, 2024)
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php.
0