CVE-2022-46158: Potential Information exposure in the upload directory in PrestaShop
PrestaShop is an open-source e-commerce solution. Versions prior to 1.7.8.8 did not properly restrict host filesystem access for users. Users may have been able to view the contents of the upload directory without appropriate permissions. This issue has been addressed and users are advised to upgrade to version 1.7.8.8. There are no known workarounds for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-46158?
CVE-2022-46158 is a vulnerability in PrestaShop, an open-source e-commerce solution, that allows users to view the contents of the upload directory without appropriate permissions.
What is the severity of CVE-2022-46158?
CVE-2022-46158 has a severity value of 4.3, which is considered medium.
How can I fix CVE-2022-46158?
To fix CVE-2022-46158, users are advised to upgrade PrestaShop to version 1.7.8.8 or later.
Where can I find more information about CVE-2022-46158?
More information about CVE-2022-46158 can be found in the following references: [GitHub Commit](https://github.com/PrestaShop/PrestaShop/commit/8684d429fb7c3bb51efb098e8b92a1fd2958f8cf) and [GitHub Security Advisory](https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-9qgp-9wwc-v29r).
What are the Common Weakness Enumeration (CWE) IDs associated with CVE-2022-46158?
CVE-2022-46158 is associated with CWE-862 (Missing Authorization) and CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor).