Skip to content

path traversal: file deletion

Moderate
matthieu-rolland published GHSA-m9r4-3fg7-pqm2 Aug 7, 2023

Package

composer prestashop/prestashop (Composer)

Affected versions

<= 8.1.0

Patched versions

8.1.1

Description

Impact

In the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path.

Patches

8.1.1

Found by

Aleksey Solovev (Positive Technologies)

Workarounds

none

References

none

Severity

Moderate
6.5
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

CVE ID

CVE-2023-39525

Weaknesses

No CWEs