PT-2023-27001 · Unknown · Prestashop

Kto94

·

Publicado

2023-08-07

·

Atualizado

2024-03-06

·

CVE-2023-39530

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions PrestaShop versions prior to 8.1.1
Description The issue allows deletion of files from the server via the CustomerMessage API. There are no known workarounds for this problem.
Recommendations For versions prior to 8.1.1, update to version 8.1.1 to resolve the issue. As a temporary workaround, consider restricting access to the CustomerMessage API until the update is applied.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-PRESTASHOP-2023-39530
CVE-2023-39530
GHSA-V4GR-V679-42P7

Produtos afetados

Prestashop