PrestaShop 漏洞列表
共找到 24 个与 PrestaShop 相关的漏洞
📅 加载漏洞趋势中...
-
PrestaShop /module/tshirtecommerce/designer SQL 注入漏洞(CVE-2023-27637) 无POC
在 PrestaShop 的 tshirtecommerce(又名自定义产品设计器)组件 2.1.4 中发现了一个问题。可以使用受损的 product_id GET 参数伪造 HTTP 请求,以利用前端控制器文件designer.php中的不安全参数,这可能导致 SQL 注入。 -
PrestaShop SQL 注入漏洞(CVE-2023-46358) 无POC
Snegurka for PrestaShop模块中的“Referral and Affiliation Program”(推荐和联盟计划)版本3.5.1及之前版本中存在漏洞。通过在方法'ReferralByPhoneDefaultModuleFrontController::ajaxProcessCartRuleValidate'中执行敏感的SQL调用,攻击者可以利用简单的HTTP请求进行SQL注入攻击,从而伪造SQL查询并获取敏感信息。 -
PrestaShop /module/askforaquote/QuotesCart SQL 注入漏洞(CVE-2023-27843) 无POC
PrestaShop是美国PrestaShop公司的一套开源的电子商务解决方案。该方案提供多种支付方式、短消息提醒和商品图片缩放等功能。 PrestaShop askforaquote v.5.4.2版本及之前版本存在安全漏洞。远程攻击者利用该漏洞通过QuotesProduct::deleteProduct组件获得权限。 -
CVE-2018-10942: Prestashop AttributeWizardPro Module - Arbitrary File Upload POC
In the Attribute Wizard addon 1.6.9 for PrestaShop allows remote attackers to execute arbitrary code by uploading a php file. -
CVE-2018-8823: PrestaShop Responsive Mega Menu Module - Remote Code Execution POC
The 'Responsive Mega Menu' module for PrestaShop is prone to a remote code execution and SQL injection vulnerability. modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop allows remote attackers to execute an SQL injection or remote code execution through function calls in the code parameter. -
CVE-2020-26248: PrestaShop Product Comments <4.2.0 - SQL Injection POC
PrestaShop Product Comments module before version 4.2.1 contains a SQL injection vulnerability, An attacker can use a blind SQL injection to retrieve data or stop the MySQL service, thereby possibly obtaining sensitive information, modifying data, and/or executing unauthorized administrative operations in the context of the affected site. -
CVE-2021-3110: PrestaShop 1.7.7.0 - SQL Injection POC
PrestaShop 1.7.7.0 contains a SQL injection vulnerability via the store system. It allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. -
CVE-2021-36748: PrestaHome Blog for PrestaShop <1.7.8 - SQL Injection POC
PrestaHome Blog for PrestaShop prior to version 1.7.8 is vulnerable to a SQL injection (blind) via the sb_category parameter. -
CVE-2021-37538: PrestaShop SmartBlog <4.0.6 - SQL Injection POC
PrestaShop SmartBlog by SmartDataSoft < 4.0.6 is vulnerable to a SQL injection vulnerability in the blog archive functionality. -
CVE-2022-22897: PrestaShop AP Pagebuilder <= 2.4.4 - SQL Injection POC
A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticated attackers to exfiltrate database data. -
CVE-2023-27032: PrestaShop AdvancedPopupCreator - SQL Injection POC
In the module “Advanced Popup Creator” (advancedpopupcreator) from Idnovate for PrestaShop, a guest can perform SQL injection in affected versions. -
CVE-2023-27637: PrestaShop `tshirtecommerce` Module - SQL Injection POC
The tshirtecommerce module for PrestaShop is vulnerable to unauthenticated SQL injection via the designer endpoint, allowing attackers to execute arbitrary SQL queries and extract sensitive information from the database. -
CVE-2023-27638: tshirtecommerce PrestaShop Module - SQL Injection POC
The tshirtecommerce module for PrestaShop is vulnerable to unauthenticated SQL injection via the tshirtecommerce_design_cart_id parameter, allowing attackers to execute arbitrary SQL queries and extract sensitive information from the database. This is due to lack of input sanitization, as shown in the patch where pSQL() is now used. -
CVE-2023-27639: PrestaShop TshirteCommerce - Directory Traversal POC
The Custom Product Designer (tshirtecommerce) module for PrestaShop allows HTTP requests to be forged using POST and GET parameters, enabling a remote attacker to perform directory traversal on the system and view the contents of code files. -
CVE-2023-27640: PrestaShop tshirtecommerce - Directory Traversal POC
The Custom Product Designer (tshirtecommerce) module for PrestaShop allows HTTP requests to be forged using POST and GET parameters, enabling a remote attacker to perform directory traversal on the system and view the contents of code files. -
CVE-2023-27847: PrestaShop xipblog - SQL Injection POC
In the blog module (xipblog), an anonymous user can perform SQL injection. Even though the module has been patched in version 2.0.1, the version number was not incremented at the time. -
CVE-2023-30150: PrestaShop leocustomajax 1.0 & 1.0.0 - SQL Injection POC
PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php. -
CVE-2023-30192: PrestaShop 'possearchproducts' <= 1.7 - SQL Injection POC
In the module “Search Products” (possearchproducts) from PosThemes for PrestaShop, a guest can perform SQL injection in affected versions. -
CVE-2023-39650: PrestaShop Theme Volty CMS Blog - SQL Injection POC
In the module 'Theme Volty CMS Blog' (tvcmsblog) up to versions 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions. -
CVE-2023-39676: PrestaShop fieldpopupnewsletter Module - Cross Site Scripting POC
Fieldpopupnewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php. -
CVE-2023-39677: PrestaShop MyPrestaModules - PhpInfo Disclosure POC
PrestaShop modules by MyPrestaModules expose PHPInfo -
CVE-2023-45375: PrestaShop PireosPay - SQL Injection POC
In the module “PireosPay” (pireospay) up to version 1.7.9 from 01generator.com for PrestaShop, a guest can perform SQL injection in affected versions. -
CVE-2023-46347: PrestaShop Step by Step products Pack - SQL Injection POC
In the module “Step by Step products Pack” (ndk_steppingpack) up to 1.5.6 from NDK Design for PrestaShop, a guest can perform SQL injection in affected versions. -
CVE-2024-36683: PrestaShop productsalert - SQL Injection POC
In the module 'Products Alert' (productsalert) up to version 1.7.4 from Smart Modules for PrestaShop, a guest can perform SQL injection in affected versions.