Show filters
121 Total Results
Displaying 91-100 of 121
Sort by:
Attacker Value
Unknown
CVE-2013-6295
Disclosure Date: February 18, 2020 (last updated February 21, 2025)
PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module
0
Attacker Value
Unknown
CVE-2013-4792
Disclosure Date: February 14, 2020 (last updated February 21, 2025)
PrestaShop before 1.4.11 allows logout CSRF.
0
Attacker Value
Unknown
CVE-2013-4791
Disclosure Date: February 14, 2020 (last updated February 21, 2025)
PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.
0
Attacker Value
Unknown
CVE-2012-2517
Disclosure Date: February 11, 2020 (last updated February 21, 2025)
Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of the product[] parameter to ajax.php.
0
Attacker Value
Unknown
CVE-2013-6358
Disclosure Date: January 23, 2020 (last updated February 21, 2025)
PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory.
0
Attacker Value
Unknown
CVE-2020-6632
Disclosure Date: January 09, 2020 (last updated February 21, 2025)
In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/default/template/header.tpl, and themes/new-theme/js/header.js.
0
Attacker Value
Unknown
CVE-2019-19595
Disclosure Date: December 05, 2019 (last updated November 27, 2024)
reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers to execute arbitrary code by uploading a .php file.
0
Attacker Value
Unknown
CVE-2019-19594
Disclosure Date: December 05, 2019 (last updated November 27, 2024)
reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute arbitrary code by uploading a .php file.
0
Attacker Value
Unknown
CVE-2019-13461
Disclosure Date: July 09, 2019 (last updated November 27, 2024)
In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure Direct Object Reference vulnerability due to a guessable value sent to the web application during checkout. An attacker could leak personal customer information. This is PrestaShop bug #14444.
0
Attacker Value
Unknown
CVE-2019-11876
Disclosure Date: May 24, 2019 (last updated November 27, 2024)
In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and conditions) before executing the malicious link.
0