CVE-2023-39526
PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through SQL injection and arbitrary file write in the back office. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.
- Affected products
- Prestashop
- Prestashop
- < 1.7.8.10, 8.0.5, 8.1.0
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 1.7% (75th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2023-08-07
CVE-2023-39526 at NVD
1 known exploit for CVE-2023-39526
Proof-of-concept code and exploit modules indexed by Sploitus