Information exposure in the upload directory in PrestaShop
28Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 5.3epss 1.6%
exploitation probability
1.6%top 26% of all CVEs
observed exploitation
nono source reports it
In PrestaShop from version 1.5.0.0 and before 1.7.6.6, there is information exposure in the upload directory. The problem is fixed in version 1.7.6.6. A possible workaround is to add an empty index.php file in the upload directory.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
PrestaShop · PrestaShop