PT-2024-21154 · Unknown+1 · Prestashop+1

Published

2024-03-03

·

Updated

2025-05-08

·

CVE-2024-25842

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PrestaShop versions prior to 9.0
Description An issue was discovered in the Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) module, allowing remote attackers to escalate privilege and obtain sensitive information. This is achieved via the uploadLogo() and postProcess() methods.
Recommendations For versions prior to 9.0, update to version 9.0 or later to resolve the issue. As a temporary workaround, consider disabling the uploadLogo() and postProcess() methods until a patch is available. Restrict access to the prestasalesmanager module to minimize the risk of exploitation.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2024-25842

Affected Products

Prestashop
Prestashop Sales Manager