Headline
GHSA-2rf5-3fw8-qm47: PrestaShop file deletion via attachment API
Impact
It is possible to delete a file from the server by using the Attachments controller and the Attachments API.
Patches
8.1.1
Found by
Kto94 (via Yeswehack)
Workarounds
none
References
none
PrestaShop file deletion via attachment API
Moderate severity GitHub Reviewed Published Aug 7, 2023 in PrestaShop/PrestaShop • Updated Aug 9, 2023
Related news
CVE-2023-39529: Merge remote-tracking branch 'ghsa-2rf5-3fw8-qm47/advisory-fix-3' int… · PrestaShop/PrestaShop@b08c647
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete a file from the server by using the Attachments controller and the Attachments API. Version 8.1.1 contains a patch for this issue. There are no known workarounds.