Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1nZjQ2LXBybTQtNTZwY84AA1LW

PrestaShop SQL manager vulnerability

Impact

Remote code execution through SQL injection and arbitrary file write in back office

Patches

1.7.8.10
8.0.5
8.1.1

Found by

Truff (via yeswehack)

Workarounds

none

References

none

Permalink: https://github.com/advisories/GHSA-gf46-prm4-56pc
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nZjQ2LXBybTQtNTZwY84AA1LW
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: over 1 year ago
Updated: about 1 year ago


CVSS Score: 9.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

EPSS Percentage: 0.00177
EPSS Percentile: 0.55046

Identifiers: GHSA-gf46-prm4-56pc, CVE-2023-39526
References: Repository: https://github.com/PrestaShop/PrestaShop
Blast Radius: 2.7

Affected Packages

packagist:prestashop/prestashop
Dependent packages: 0
Dependent repositories: 2
Downloads: 6,727 total
Affected Version Ranges: < 1.7.8.10, >= 8.0.0, < 8.0.5, = 8.1.0
Fixed in: 1.7.8.10, 8.0.5, 8.1.1
All affected versions: 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5, 8.1.6, 8.1.7, 8.2.0
All unaffected versions: