CVE-2023-39530: PrestaShop vulnerable to file deletion via CustomerMessage
Impact It is possible to delete files from the server via the CustomerMessage API
Patches 8.1.1
Found by Kto94 (via Yeswehack)
Workarounds none
References none
Other sources
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete files from the server via the CustomerMessage API. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-39530.
What is the impact of this vulnerability?
The impact of this vulnerability is the possibility to delete files from the server via the CustomerMessage API.
What is the severity of CVE-2023-39530?
The severity of CVE-2023-39530 is critical (9.1).
How can I fix CVE-2023-39530?
To fix CVE-2023-39530, you need to update to version 8.1.1 of PrestaShop, which contains a patch for this issue.
Are there any known workarounds for CVE-2023-39530?
No, there are no known workarounds for CVE-2023-39530.