prestashop/prestashop Security Advisories for 1.7.6.3 (17)
-
PrestaShop allows users to uninstall modules from backoffice, even with low rights
Affected version: <8.1.2
Reported by:
GitHub -
PrestaShop allows employee without any access rights to list all installed modules
Affected version: <8.1.2
Reported by:
GitHub -
Reported by:
GitHub -
Reported by:
GitHub -
Reported by:
GitHub -
PrestaShop XSS injection through Validate::isCleanHTML method
Affected version: <1.7.8.10|>=8.0.0,<8.0.5|=8.1.0
Reported by:
GitHub -
PrestaShop SQL manager vulnerability
Affected version: <1.7.8.10|>=8.0.0,<8.0.5|=8.1.0
Reported by:
GitHub -
Reported by:
GitHub -
Reported by:
GitHub -
Reported by:
GitHub -
Possible XSS injection through Validate::isCleanHTML method
Affected version: <1.7.8.9|>=8.0.0,<8.0.4
Reported by:
GitHub -
SQL filter bypass leading to arbitrary write requests using "SQL Manager"
Affected version: <1.7.8.9|>=8.0.0,<8.0.4
Reported by:
GitHub -
Reported by:
GitHub -
PrestaShop has potential Information exposure in the upload directory
Affected version: <1.7.8.8
Reported by:
GitHub -
PrestaShop eval injection possible if shop vulnerable to SQL injection
Affected version: >=1.6.0.10,<1.7.8.7
Reported by:
GitHub -
Reported by:
GitHub -
Reported by:
GitHub