Friends-Of-Presta Security Advisories
Cybersecurity GlossaryAbout
    • Jun 1, 2023 • #module • medium (6.5)

      [CVE-2023-3031] Improper Limitation of a Pathname to a Restricted Directory in Webbax - King-Avis module for PrestaShop

      Improper Limitation of a Pathname leads to a Path Traversal vulnerability in the module King-Avis for Prestashop, allowing a user knowing the download token to read arbitrary local files.This issue affects King-Avis: before 17.3.15.

    • Jun 1, 2023 • #module • critical (9.8)

      [CVE-2023-30149] Improper neutralization of SQL parameter in the City Autocomplete (cityautocomplete) module from ebewe.net for PrestaShop

      SQL injection vulnerability in the City Autocomplete (cityautocomplete) module from ebewe.net for PrestaShop, prior to version 1.8.12 (for PrestaShop version 1.5/1.6) or prior to 2.0.3 (for PrestaShop version 1.7), allows remote attackers to execute arbitrary SQL commands via the type, input_name. or q parameter in the autocompletion.php front controller.

    • May 30, 2023 • #modules • high (7.5), GDPR violation

      [CVE-2023-30197] Improper Limitation of a Pathname to a Restricted Directory in Webbax - My inventory module for PrestaShop

      In the module “My inventory” (myinventory) from Webbax for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack.

    • May 25, 2023 • #modules • critical (9.8)

      [CVE-2023-33280] Improper neutralization of multiple SQL parameters in the scquickaccounting module for PrestaShop

      In the module “SC Quick Accounting” (scquickaccounting), an anonymous user can perform a SQL injection. The module have been patched in version 3.7.4.

    • May 25, 2023 • #modules • critical (9.8)

      [CVE-2023-33279] Improper neutralization of multiple SQL parameters in the SC Fix My PrestaShop module for PrestaShop

      In the module “SC Fix My PrestaShop” (scfixmyprestashop), an anonymous user can perform a SQL injection. The module is obsolete and must be deleted.

    • May 25, 2023 • #modules • critical (9.8)

      [CVE-2023-33278] Improper neutralization of multiple SQL parameters in the scexportcustomers module for PrestaShop

      In the module “SC Export Customers” (scexportcustomers), an anonymous user can perform SQL injections. The module have been patched in version 3.6.2.

    • May 22, 2023 • #modules • high (7.5), GDPR violation

      [CVE-2023-30196] Improper Limitation of a Pathname to a Restricted Directory in Webbax - Sales Booster module for PrestaShop

      In the module “Sales Booster” (salesbooster) from Webbax for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack.

    • May 17, 2023 • #modules • critical (9.8)

      [CVE-2023-30191] Improper neutralization of SQL parameter in Prestaeg - CDesigner module for PrestaShop

      In the module “CDesigner” (cdesigner) from Prestaeg for PrestaShop, a guest can perform SQL injection in affected versions.

    • May 16, 2023 • #modules • high (7.5), GDPR violation

      [CVE-2023-30199] Improper Limitation of a Pathname to a Restricted Directory in Webbax - Custom Exporter module for PrestaShop

      In the module “Custom Exporter” (customexporter) from Webbax for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack.

    • May 11, 2023 • #modules • critical (9.8)

      [CVE-2023-30192] Improper neutralization of SQL parameter in PosThemes - Search Products for PrestaShop

      In the module “Search Products” (possearchproducts) from PosThemes for PrestaShop, a guest can perform SQL injection in affected versions.

    « Prev 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 Next »

    Subscribe

    • Friends Of Presta

    Friends Of Presta is a none profit organization that supports the open-source ecommerce platform PrestaShop.