Lack of data validation - Path Traversal In prestashop/prestashop
Description
PrestaShop path traversal
Impact
In the back office, files can be compromised using path traversal by replaying the import file deletion query with a specified file path, using traversal path.
Patches
8.1.1
Found by
Aleksey Solovev (Positive Technologies)
Workarounds
none
References
none
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 8.1.1 |
Aliases
1. 2. 3. 4. 5.
References
1. 2.