PrestaShop path traversal
Moderate severity
GitHub Reviewed
Published
Aug 7, 2023
in
PrestaShop/PrestaShop
•
Updated Nov 12, 2023
Description
Published by the National Vulnerability Database
Aug 7, 2023
Published to the GitHub Advisory Database
Aug 9, 2023
Reviewed
Aug 9, 2023
Last updated
Nov 12, 2023
Impact
In the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path.
Patches
8.1.1
Found by
Aleksey Solovev (Positive Technologies)
Workarounds
none
References
none
References