Skip to main content

CVE-2023-39526

Description

PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through SQL injection and arbitrary file write in the back office. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.

NVD
Severity: CRITICAL
CVE ID: CVE-2023-39526
CVSS Score: 9.8
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
GitHub, Inc.
Severity: CRITICAL
CVE ID: CVE-2023-39526
CVSS Score: 9.1
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Refrence: NVDMITRE

Proof Of Concept

dnkhack

Prestashop fix vulnerability CVE-2023-39526 & CVE-2023-39527

Refrence: GitHub