BIT-prestashop-2023-39528

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/prestashop/BIT-prestashop-2023-39528.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-prestashop-2023-39528
Aliases
Published
2024-03-06T11:03:22.395Z
Modified
2024-11-27T19:40:48.342Z
Summary
[none]
Details

PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, the displayAjaxEmailHTML method can be used to read any file on the server, potentially even outside of the project if the server is not correctly configured. Version 8.1.1 contains a patch for this issue. There are no known workarounds.

Database specific
{
    "cpes": [
        "cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / prestashop

Package

Name
prestashop
Purl
pkg:bitnami/prestashop

Severity

  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.1.1