CVE-2020-5278
- EPSS 0.22%
- Veröffentlicht 20.04.2020 17:15:15
- Zuletzt bearbeitet 21.11.2024 05:33:49
In PrestaShop between versions 1.5.4.0 and 1.7.6.5, there is a reflected XSS on Exception page The problem is fixed in 1.7.6.5
CVE-2020-5279
- EPSS 0.17%
- Veröffentlicht 20.04.2020 17:15:15
- Zuletzt bearbeitet 21.11.2024 05:33:49
In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for legacy controllers. - admin-dev/index.php/configure/shop/customer-preferences/ - admin-dev/index.php/improve/international/transla...
CVE-2020-5250
- EPSS 0.63%
- Veröffentlicht 05.03.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:45
In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the form, and thus steal someone else's address. It is the same with CustomerForm, you are able to change the id_customer and change a...
CVE-2013-6295
- EPSS 0.32%
- Veröffentlicht 18.02.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 01:58:57
PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module
CVE-2013-4791
- EPSS 0.21%
- Veröffentlicht 14.02.2020 00:15:10
- Zuletzt bearbeitet 21.11.2024 01:56:25
PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.
CVE-2013-4792
- EPSS 0.1%
- Veröffentlicht 14.02.2020 00:15:10
- Zuletzt bearbeitet 21.11.2024 01:56:25
PrestaShop before 1.4.11 allows logout CSRF.
CVE-2012-2517
- EPSS 0.86%
- Veröffentlicht 11.02.2020 20:15:10
- Zuletzt bearbeitet 21.11.2024 01:39:10
Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of the product[] parameter to ajax.php.
- EPSS 3%
- Veröffentlicht 23.01.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 01:59:04
PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory.
CVE-2020-6632
- EPSS 0.33%
- Veröffentlicht 09.01.2020 02:15:13
- Zuletzt bearbeitet 21.11.2024 05:36:04
In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/default/template/header.tpl, and themes/new-theme/js/header.js.
CVE-2019-19594
- EPSS 5.56%
- Veröffentlicht 05.12.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:00
reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute arbitrary code by uploading a .php file.