← back
CVE-2020-15081mediumCWE-548

Information exposure in the upload directory in PrestaShop

28Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 5.3epss 1.6%
exploitation probability
1.6%top 26% of all CVEs
observed exploitation
nono source reports it
In PrestaShop from version 1.5.0.0 and before 1.7.6.6, there is information exposure in the upload directory. The problem is fixed in version 1.7.6.6. A possible workaround is to add an empty index.php file in the upload directory.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
PrestaShop · PrestaShop