- EPSS 3.72%
- Veröffentlicht 23.01.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 01:59:04
PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory.
CVE-2020-6632
- EPSS 0.68%
- Veröffentlicht 09.01.2020 02:15:13
- Zuletzt bearbeitet 21.11.2024 05:36:04
In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/default/template/header.tpl, and themes/new-theme/js/header.js.
CVE-2019-19594
- EPSS 4%
- Veröffentlicht 05.12.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:00
reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute arbitrary code by uploading a .php file.
CVE-2019-19595
- EPSS 4%
- Veröffentlicht 05.12.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:01
reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers to execute arbitrary code by uploading a .php file.
CVE-2019-13461
- EPSS 1.68%
- Veröffentlicht 09.07.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:24:56
In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure Direct Object Reference vulnerability due to a guessable value sent to the web application during checkout. An attacker could leak...
CVE-2019-11876
- EPSS 0.89%
- Veröffentlicht 24.05.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:56
In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and ...
CVE-2018-20717
- EPSS 2.71%
- Veröffentlicht 15.01.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:01
In the orders section of PrestaShop before 1.7.2.5, an attack is possible after gaining access to a target store with a user role with the rights of at least a Salesman or higher privileges. The attacker can then inject arbitrary PHP objects into the...
CVE-2018-19355
- EPSS 3.5%
- Veröffentlicht 19.11.2018 00:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:47
modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a php file via modules/orderfiles/upload.php with auptype equal to produc...
CVE-2018-19124
- EPSS 2.89%
- Veröffentlicht 09.11.2018 11:29:03
- Zuletzt bearbeitet 21.11.2024 03:57:22
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 on Windows allows remote attackers to write to arbitrary image files.
CVE-2018-19125
- EPSS 10.76%
- Veröffentlicht 09.11.2018 11:29:03
- Zuletzt bearbeitet 21.11.2024 03:57:22
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to delete an image directory.