PT-2023-26999 · Unknown · Prestashop

·

CVE-2023-39528

·

Published

2023-08-07

·

Updated

2024-03-06

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions PrestaShop versions prior to 8.1.1
Description The issue concerns the displayAjaxEmailHTML method, which can be used to read any file on the server, potentially even outside of the project if the server is not correctly configured. This could potentially lead to a Remote Code Execution (RCE) vulnerability when combined with the Deserialization of Untrusted Data.
Recommendations For PrestaShop versions prior to 8.1.1, update to version 8.1.1 to resolve the issue. As a temporary workaround, consider restricting access to the displayAjaxEmailHTML method until the patch is applied.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-PRESTASHOP-2023-39528
CVE-2023-39528
GHSA-HPF4-V7V2-95P2

Affected Products

Prestashop