BIT-prestashop-2023-39528

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/prestashop/BIT-prestashop-2023-39528.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-prestashop-2023-39528
Withdrawn
2026-07-16T09:00:05Z
Published
2024-03-06T11:03:22Z
Modified
2026-07-16T09:11:45Z
Summary
PrestaShop vulnerable to file reading through path traversal
Details

PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, the displayAjaxEmailHTML method can be used to read any file on the server, potentially even outside of the project if the server is not correctly configured. Version 8.1.1 contains a patch for this issue. There are no known workarounds.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*"
    ],
    "severity":  "High"
}
References

Affected packages

Bitnami / prestashop

Package

Name
prestashop
Purl
pkg:bitnami/prestashop

Severity

  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.1.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/prestashop/BIT-prestashop-2023-39528.json"