PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vulnerability. A BO user can write, update, and delete in the database, even without having specific rights. PrestaShop 8.0.4 and 1.7.8.9 contain a patch for this issue. There are no known workarounds.
2023-04-25T19:15:11.247
2024-11-21T08:00:56.873
Modified
CVSSv3.1: 9.9 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | prestashop | prestashop | < 1.7.8.9 | Yes |
Application | prestashop | prestashop | < 8.0.4 | Yes |