CVE-2023-39529: PrestaShop vulnerable to file deletion via attachment API
Impact It is possible to delete a file from the server by using the Attachments controller and the Attachments API.
Patches 8.1.1
Found by Kto94 (via Yeswehack)
Workarounds none
References none
Other sources
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete a file from the server by using the Attachments controller and the Attachments API. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the impact of CVE-2023-39529?
It is possible to delete a file from the server by using the Attachments controller and the Attachments API in PrestaShop prior to version 8.1.1.
How can I fix CVE-2023-39529?
Upgrade to version 8.1.1 of PrestaShop, which contains a patch for this vulnerability.
Are there any workarounds for CVE-2023-39529?
There are no known workarounds for this vulnerability.
What is the severity of CVE-2023-39529?
The severity of CVE-2023-39529 is critical with a CVSS score of 9.1.
What is the CWE category for CVE-2023-39529?
The CWE category for CVE-2023-39529 is CWE-20: Improper Input Validation.