First published: Mon Aug 07 2023(Updated: )
### Impact It is possible to delete files from the server via the CustomerMessage API ### Patches 8.1.1 ### Found by Kto94 (via Yeswehack) ### Workarounds none ### References none
Credit: security-advisories@github.com security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Prestashop Prestashop | <8.1.1 | |
composer/prestashop/prestashop | <=8.1.0 | 8.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-39530.
The impact of this vulnerability is the possibility to delete files from the server via the CustomerMessage API.
The severity of CVE-2023-39530 is critical (9.1).
To fix CVE-2023-39530, you need to update to version 8.1.1 of PrestaShop, which contains a patch for this issue.
No, there are no known workarounds for CVE-2023-39530.