Prestashop

Prestashop

100 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 02.07.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:04:46

In PrestaShop from version 1.5.0.0 and before 1.7.6.6, there is information exposure in the upload directory. The problem is fixed in version 1.7.6.6. A possible workaround is to add an empty index.php file in the upload directory.

  • EPSS 0.21%
  • Veröffentlicht 02.07.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:04:46

In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and others should not be accessible. The problem is fixed in version 1.7.6.6 A possible workaround is to make sure `composer.json` and `do...

  • EPSS 0.15%
  • Veröffentlicht 02.07.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:04:46

In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module Manager and Module Positions. The problem is fixed in version 1.7.6.6

  • EPSS 0.21%
  • Veröffentlicht 02.07.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:56:43

In PrestaShop from version 1.5.3.0 and before version 1.7.6.6, there is a stored XSS when using the name of a quick access item. The problem is fixed in 1.7.6.6.

  • EPSS 0.21%
  • Veröffentlicht 20.04.2020 17:15:16
  • Zuletzt bearbeitet 21.11.2024 05:33:51

In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations, attachments and specific prices. The problem is fixed in 1.7.6.5.

  • EPSS 0.17%
  • Veröffentlicht 20.04.2020 17:15:16
  • Zuletzt bearbeitet 21.11.2024 05:33:50

"In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there is improper access controls on product attributes page. The problem is fixed in 1.7.6.5.

  • EPSS 0.17%
  • Veröffentlicht 20.04.2020 17:15:16
  • Zuletzt bearbeitet 21.11.2024 05:33:50

In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is fixed in 1.7.6.5.

  • EPSS 0.22%
  • Veröffentlicht 20.04.2020 17:15:16
  • Zuletzt bearbeitet 21.11.2024 05:33:50

In PrestaShop between versions 1.7.4.0 and 1.7.6.5, there is a reflected XSS when uploading a wrong file. The problem is fixed in 1.7.6.5

  • EPSS 0.22%
  • Veröffentlicht 20.04.2020 17:15:16
  • Zuletzt bearbeitet 21.11.2024 05:33:50

In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is a reflected XSS with `back` parameter. The problem is fixed in 1.7.6.5

  • EPSS 0.22%
  • Veröffentlicht 20.04.2020 17:15:15
  • Zuletzt bearbeitet 21.11.2024 05:33:49

In PrestaShop between versions 1.7.1.0 and 1.7.6.5, there is a reflected XSS on AdminCarts page with `cartBox` parameter The problem is fixed in 1.7.6.5