CVE-2023-39526
PrestaShopSQL manager vulnerability (potential RCE)
9.1
CRITICAL
CVSS 3.1
EPSS 1.3%
Description
PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through SQL injection and arbitrary file write in the back office. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.
How to fix CVE-2023-39526
To remediate CVE-2023-39526, upgrade the affected package to a fixed version below.
- —upgrade to 8.1.1 or later
Is CVE-2023-39526 being exploited?
Low — EPSS is 1.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 8.1.0, < 8.1.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |