Prestashop

Prestashop

100 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.1%
  • Veröffentlicht 14.02.2020 00:15:10
  • Zuletzt bearbeitet 21.11.2024 01:56:25

PrestaShop before 1.4.11 allows logout CSRF.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 14.02.2020 00:15:10
  • Zuletzt bearbeitet 21.11.2024 01:56:25

PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.

Exploit
  • EPSS 0.86%
  • Veröffentlicht 11.02.2020 20:15:10
  • Zuletzt bearbeitet 21.11.2024 01:39:10

Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of the product[] parameter to ajax.php.

Exploit
  • EPSS 3.16%
  • Veröffentlicht 23.01.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 01:59:04

PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory.

  • EPSS 0.33%
  • Veröffentlicht 09.01.2020 02:15:13
  • Zuletzt bearbeitet 21.11.2024 05:36:04

In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/default/template/header.tpl, and themes/new-theme/js/header.js.

Exploit
  • EPSS 5.56%
  • Veröffentlicht 05.12.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:01

reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers to execute arbitrary code by uploading a .php file.

Exploit
  • EPSS 5.56%
  • Veröffentlicht 05.12.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:00

reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute arbitrary code by uploading a .php file.

Exploit
  • EPSS 0.37%
  • Veröffentlicht 09.07.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:24:56

In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure Direct Object Reference vulnerability due to a guessable value sent to the web application during checkout. An attacker could leak...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 24.05.2019 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:21:56

In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and ...

Exploit
  • EPSS 2.99%
  • Veröffentlicht 15.01.2019 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:02:01

In the orders section of PrestaShop before 1.7.2.5, an attack is possible after gaining access to a target store with a user role with the rights of at least a Salesman or higher privileges. The attacker can then inject arbitrary PHP objects into the...