Lack of data validation In prestashop/prestashop
Description
PrestaShop file deletion via attachment API
Impact
It is possible to delete a file from the server by using the Attachments controller and the Attachments API.
Patches
8.1.1
Found by
Kto94 (via Yeswehack)
Workarounds
none
References
none
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 8.1.1 |
Aliases
1. 2. 3. 4. 5.
References
1. 2.