CVE-2024-26469
- EPSS 0.27%
- Veröffentlicht 03.03.2024 10:15:06
- Zuletzt bearbeitet 13.05.2025 14:22:16
Server-Side Request Forgery (SSRF) vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to cause a denial of service (DoS) and escalate privileges via the url paramete...
CVE-2024-26129
- EPSS 0.3%
- Veröffentlicht 19.02.2024 22:15:49
- Zuletzt bearbeitet 17.01.2025 15:44:18
PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure in a JavaScript variable. A patch is available in version 8.1.4.
CVE-2024-21628
- EPSS 0.38%
- Veröffentlicht 02.01.2024 22:15:09
- Zuletzt bearbeitet 21.11.2024 08:54:45
PrestaShop is an open-source e-commerce platform. Prior to version 8.1.3, the isCleanHtml method is not used on this this form, which makes it possible to store a cross-site scripting payload in the database. The impact is low because the HTML is not...
CVE-2024-21627
- EPSS 0.95%
- Veröffentlicht 02.01.2024 21:15:10
- Zuletzt bearbeitet 21.11.2024 08:54:45
PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not detected by the `isCleanHTML` method. Some modules using the `isCleanHTML` method could be vulnerable to cross-site scripting. Versi...
CVE-2023-43663
- EPSS 0.1%
- Veröffentlicht 28.09.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 08:24:34
PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit ...
CVE-2023-43664
- EPSS 0.24%
- Veröffentlicht 28.09.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 08:24:34
PrestaShop is an Open Source e-commerce web application. In the Prestashop Back office interface, an employee can list all modules without any access rights: method `ajaxProcessGetPossibleHookingListForModule` doesn't check access rights. This issue ...
CVE-2023-39525
- EPSS 1.22%
- Veröffentlicht 07.08.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 08:15:36
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, in the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path that uses the traversal path. Ve...
CVE-2023-39526
- EPSS 13.76%
- Veröffentlicht 07.08.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 08:15:36
PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through SQL injection and arbitrary file write in the back office. Versions 1.7.8.10, 8.0.5, and 8.1.1 conta...
CVE-2023-39527
- EPSS 1.88%
- Veröffentlicht 07.08.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 08:15:36
PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to cross-site scripting through the `isCleanHTML` method. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known wor...
CVE-2023-39528
- EPSS 0.79%
- Veröffentlicht 07.08.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 08:15:36
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, the `displayAjaxEmailHTML` method can be used to read any file on the server, potentially even outside of the project if the server is not correctly configured. Version ...