Prestashop

Prestashop

107 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.79%
  • Veröffentlicht 20.04.2020 17:15:15
  • Zuletzt bearbeitet 21.11.2024 05:33:48

In PrestaShop between versions 1.6.0.0 and 1.7.6.5, there is a reflected XSS with `date_from` and `date_to` parameters in the dashboard page This problem is fixed in 1.7.6.5

  • EPSS 0.83%
  • Veröffentlicht 20.04.2020 17:15:15
  • Zuletzt bearbeitet 21.11.2024 05:33:48

In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is a reflected XSS on Search page with `alias` and `search` parameters. The problem is patched in 1.7.6.5

  • EPSS 0.79%
  • Veröffentlicht 20.04.2020 17:15:15
  • Zuletzt bearbeitet 21.11.2024 05:33:49

In PrestaShop between versions 1.7.1.0 and 1.7.6.5, there is a reflected XSS on AdminCarts page with `cartBox` parameter The problem is fixed in 1.7.6.5

  • EPSS 0.79%
  • Veröffentlicht 20.04.2020 17:15:15
  • Zuletzt bearbeitet 21.11.2024 05:33:49

In PrestaShop between versions 1.5.4.0 and 1.7.6.5, there is a reflected XSS on Exception page The problem is fixed in 1.7.6.5

  • EPSS 0.79%
  • Veröffentlicht 20.04.2020 17:15:15
  • Zuletzt bearbeitet 21.11.2024 05:33:49

In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for legacy controllers. - admin-dev/index.php/configure/shop/customer-preferences/ - admin-dev/index.php/improve/international/transla...

  • EPSS 0.85%
  • Veröffentlicht 05.03.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:33:45

In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the form, and thus steal someone else's address. It is the same with CustomerForm, you are able to change the id_customer and change a...

Exploit
  • EPSS 2.29%
  • Veröffentlicht 18.02.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 01:58:57

PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module

Exploit
  • EPSS 0.56%
  • Veröffentlicht 14.02.2020 00:15:10
  • Zuletzt bearbeitet 21.11.2024 01:56:25

PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.

Exploit
  • EPSS 0.28%
  • Veröffentlicht 14.02.2020 00:15:10
  • Zuletzt bearbeitet 21.11.2024 01:56:25

PrestaShop before 1.4.11 allows logout CSRF.

Exploit
  • EPSS 1.89%
  • Veröffentlicht 11.02.2020 20:15:10
  • Zuletzt bearbeitet 21.11.2024 01:39:10

Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of the product[] parameter to ajax.php.