Headline
GHSA-m9r4-3fg7-pqm2: PrestaShop path traversal
Impact
In the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path.
Patches
8.1.1
Found by
Aleksey Solovev (Positive Technologies)
Workarounds
none
References
none
PrestaShop path traversal
Moderate severity GitHub Reviewed Published Aug 7, 2023 in PrestaShop/PrestaShop • Updated Aug 9, 2023
Related news
CVE-2023-39525: path traversal: file deletion
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, in the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path that uses the traversal path. Version 8.1.1 contains a patch for this issue. There are no known workarounds.