CVE-2023-39526: PrestaShopSQL manager vulnerability (potential RCE)
Impact Remote code execution through SQL injection and arbitrary file write in back office
Patches 1.7.8.10 8.0.5 8.1.1
Found by Truff (via yeswehack)
Workarounds none
References none
Other sources
PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through SQL injection and arbitrary file write in the back office. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-39526.
What is the impact of this vulnerability?
The impact of this vulnerability is remote code execution through SQL injection and arbitrary file write in the back office.
Which versions of PrestaShop are affected by this vulnerability?
Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 of PrestaShop are affected by this vulnerability.
Are there any known workarounds for this vulnerability?
No, there are no known workarounds for this vulnerability.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [Link 1](https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-gf46-prm4-56pc), [Link 2](https://nvd.nist.gov/vuln/detail/CVE-2023-39526), [Link 3](https://github.com/PrestaShop/PrestaShop/commit/817847e2347844a9b6add017581f1932bcd28c09).