NA

CVE-2023-39526

Published: 07/08/2023 Updated: 09/08/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

PrestaShop is an open source e-commerce web application. Versions before 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through SQL injection and arbitrary file write in the back office. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

prestashop prestashop 8.1.0

prestashop prestashop

Github Repositories

Prestashop fix vulnerability CVE-2023-39526 & CVE-2023-39527

fix CVE 2023_39526 (GHSA-gf46-prm4-56pc) githubcom/advisories/GHSA-gf46-prm4-56pc CVE 2023_39527 (GHSA-xw2r-f8xv-c8xp) githubcom/advisories/GHSA-xw2r-f8xv-c8xp Prestashop fix vulnerability CVE-2023-39526 & CVE-2023-39527