Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-41497
HistoryMay 23, 2023 - 12:00 a.m.

Prestashop path traversal vulnerability (CNVD-2023-41497)

2023-05-2300:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
prestashop
e-commerce
path traversal
vulnerability
payment methods
alerts
product image scaling
permissions control
pathname construction control
information system
files

EPSS

0.001

Percentile

50.9%

PrestaShop is an open source e-commerce solution from PrestaShop, Inc. in the United States. The solution provides a variety of payment methods, short message alerts and product image scaling and other features. Prestashop 1.7.20 and previous versions of the existence of path traversal vulnerability , the vulnerability stems from odules/customexporter/downloads/download.php lack of permissions control and pathname construction control , an attacker can use the vulnerability through the path traversal to view the information system of all the files .

EPSS

0.001

Percentile

50.9%

Related for CNVD-2023-41497