Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1nZjQ2LXBybTQtNTZwY84AA1LW

PrestaShop SQL manager vulnerability

Impact

Remote code execution through SQL injection and arbitrary file write in back office

Patches

1.7.8.10
8.0.5
8.1.1

Found by

Truff (via yeswehack)

Workarounds

none

References

none

Permalink: https://github.com/advisories/GHSA-gf46-prm4-56pc
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nZjQ2LXBybTQtNTZwY84AA1LW
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: 9 months ago
Updated: 6 months ago


CVSS Score: 9.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Identifiers: GHSA-gf46-prm4-56pc, CVE-2023-39526
References: Repository: https://github.com/PrestaShop/PrestaShop
Blast Radius: 2.7

Affected Packages

packagist:prestashop/prestashop
Dependent packages: 0
Dependent repositories: 2
Downloads: 3,526 total
Affected Version Ranges: < 1.7.8.10, >= 8.0.0, < 8.0.5, = 8.1.0
Fixed in: 1.7.8.10, 8.0.5, 8.1.1
All affected versions: 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5
All unaffected versions: