BIT-prestashop-2023-39526

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/prestashop/BIT-prestashop-2023-39526.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-prestashop-2023-39526
Aliases
Published
2024-03-06T11:03:44.012Z
Modified
2024-11-27T19:40:48.342Z
Summary
[none]
Details

PrestaShop is an open source e-commerce web application. Versions prior to 8.0.5, and 8.1.1 are vulnerable to remote code execution through SQL injection and arbitrary file write in the back office. Versions 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.

Database specific
{
    "cpes": [
        "cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:prestashop:prestashop:8.1.0:*:*:*:*:*:*:*"
    ],
    "severity": "Critical"
}
References

Affected packages

Bitnami / prestashop

Package

Name
prestashop
Purl
pkg:bitnami/prestashop

Severity

  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.0.0
Fixed
8.0.5
Type
SEMVER
Events
Introduced
8.1.0
Last affected
8.1.0