GHSA-83j2-qhx2-p7jc

Suggest an improvement
Source
https://github.com/advisories/GHSA-83j2-qhx2-p7jc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-83j2-qhx2-p7jc/GHSA-83j2-qhx2-p7jc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-83j2-qhx2-p7jc
Aliases
Published
2023-11-08T17:53:14Z
Modified
2024-02-16T08:22:29.806131Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H CVSS Calculator
Summary
PrestaShop blockreassurance BO User can remove any file from server when adding a and deleting a block
Details

Impact

When adding a block in blockreassurance module, a BO user can modify the http request and give the path of any file in the project instead of an image. When deleting the block from the BO, the file will be deleted.

It is possible to make the website completely unavailable by removing index.php for example.

Patches

v5.1.4

Workarounds

No workaround available

References

Database specific
{
    "nvd_published_at": "2023-11-08T22:15:10Z",
    "cwe_ids": [
        "CWE-285"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-11-08T17:53:14Z"
}
References

Affected packages

Packagist / prestashop/blockreassurance

Package

Name
prestashop/blockreassurance
Purl
pkg:composer/prestashop/blockreassurance

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.1.4

Affected versions

v1.*

v1.0.1
v1.0.5
v1.0.6

v2.*

v2.0.0
v2.0.1
v2.0.2
v2.0.3

v3.*

v3.0.0
v3.0.1

v4.*

v4.1.0
v4.1.1

v5.*

v5.0.0
v5.1.0
v5.1.1
v5.1.2
v5.1.3

Database specific

{
    "last_known_affected_version_range": "<= 5.1.3"
}