PT-2023-26996 · Unknown · Prestashop

·

CVE-2023-39525

·

Publicado

2023-08-07

·

Atualizado

2024-03-06

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions PrestaShop versions prior to 8.1.1
Description The issue allows files to be compromised using path traversal by replaying the import file deletion query with a specified file path that uses the traversal path in the back office. There are no known workarounds.
Recommendations For PrestaShop versions prior to 8.1.1, update to version 8.1.1 to resolve the issue. As a temporary workaround, consider restricting access to the import file deletion query to minimize the risk of exploitation.

Exploit

Correção

DoS

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-PRESTASHOP-2023-39525
CVE-2023-39525
GHSA-M9R4-3FG7-PQM2

Produtos afetados

Prestashop