CVE-2023-39525: PrestaShop vulnerable to path traversal
Impact In the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path.
Patches 8.1.1
Found by Aleksey Solovev (Positive Technologies)
Workarounds none
References none
Other sources
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, in the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path that uses the traversal path. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the impact of CVE-2023-39525?
In the back office of PrestaShop, files can be compromised using path traversal, allowing an attacker to replay an import file deletion query with a specified file path.
What is the severity of CVE-2023-39525?
CVE-2023-39525 has a severity rating of 9.1 (Critical).
How can an attacker exploit CVE-2023-39525?
An attacker can exploit CVE-2023-39525 by manipulating the import file deletion query and using a traversal path to compromise files in the PrestaShop back office.
Is there a patch available for CVE-2023-39525?
Yes, version 8.1.1 of PrestaShop contains a patch for CVE-2023-39525.
Where can I find more information about CVE-2023-39525?
You can find more information about CVE-2023-39525 on the GitHub Security Advisory, the NIST National Vulnerability Database, and the GitHub commit page.