Vulnerabilities
Vulnerable Software
Prestashop:  Security Vulnerabilities
In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for legacy controllers. - admin-dev/index.php/configure/shop/customer-preferences/ - admin-dev/index.php/improve/international/translations/ - admin-dev/index.php/improve/international/geolocation/ - admin-dev/index.php/improve/international/localization - admin-dev/index.php/configure/advanced/performance - admin-dev/index.php/sell/orders/delivery-slips/ - admin-dev/index.php?controller=AdminStatuses The problem is fixed in 1.7.6.5
CVSS Score
4.1
EPSS Score
0.008
Published
2020-04-20
In the ps_link module for PrestaShop before version 3.1.0, there is a stored XSS when you create or edit a link list block with the title field. The problem is fixed in 3.1.0
CVSS Score
4.4
EPSS Score
0.006
Published
2020-04-16
In PrestaShop module ps_linklist versions before 3.1.0, there is a stored XSS when using custom URLs. The problem is fixed in version 3.1.0
CVSS Score
4.1
EPSS Score
0.007
Published
2020-04-16
PrestaShop module ps_facetedsearch versions before 2.1.0 has a reflected XSS with social networks fields The problem is fixed in 2.1.0
CVSS Score
4.1
EPSS Score
0.007
Published
2020-04-16
PrestaShop module ps_facetedsearch versions before 3.5.0 has a reflected XSS with `url_name` parameter. The problem is fixed in 3.5.0
CVSS Score
4.1
EPSS Score
0.007
Published
2020-03-25
In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the form, and thus steal someone else's address. It is the same with CustomerForm, you are able to change the id_customer and change all information of all accounts. The problem is patched in version 1.7.6.4.
CVSS Score
7.6
EPSS Score
0.009
Published
2020-03-05
PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module
CVSS Score
9.8
EPSS Score
0.023
Published
2020-02-18
PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.
CVSS Score
5.4
EPSS Score
0.006
Published
2020-02-14
PrestaShop before 1.4.11 allows logout CSRF.
CVSS Score
5.5
EPSS Score
0.003
Published
2020-02-14
Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of the product[] parameter to ajax.php.
CVSS Score
6.1
EPSS Score
0.019
Published
2020-02-11


Contact Us

Shodan ® - All rights reserved