IMPORTANT NOTICE: DO NOT REPORT VULNERABILITIES SOLELY TO THE AUTHOR OR MARKETPLACE.
We urge you to report any vulnerabilities directly to us. Our mission is to ensure the safety and security of the PrestaShop ecosystem. Unfortunately, many module developers may not always recognize or acknowledge the vulnerabilities in their code, whether due to lack of awareness, or inability to properly evaluate the associated risk, or other reasons.
Given the rise in professional cybercrime networks actively seeking out these vulnerabilities, it's crucial that any potential threats are promptly addressed and the community is informed. The most effective method to do this is by publishing a CVE, like the one provided below.
Should you discover any vulnerabilities, please report them to us at: report[@]security-presta.org or visit https://security-presta.org for more information.
Every vulnerability report helps make the community more secure, and we are profoundly grateful for any information shared with us.
-
[CVE-2023-46355] Exposure of Private Personal Information to an Unauthorized Actor in Bl Modules - CSV Feeds PRO module for PrestaShop
In the module “CSV Feeds PRO” (csvfeeds) up to version 2.5.2 from Bl Modules for PrestaShop, a guest can download personal information without restriction if the administrator do not force password on feeds.
-
[CVE-2023-46357] Improper neutralization of SQL parameter in MyPrestaModules - Cross Selling in Modal Cart module for PrestaShop
In the module “Cross Selling in Modal Cart” (motivationsale) from MyPrestaModules for PrestaShop, a guest can perform SQL injection in affected versions.
-
[CVE-2023-45377] Improper neutralization of SQL parameter in Chronopost - Chronopost Official module for PrestaShop
In the module “Chronopost Official” (chronopost) up to version 6.4.0 from Chronopost for PrestaShop, a guest can perform SQL injection in affected versions if the module is not installed OR if a secret accessible to administrator is stolen.
-
[CVE-2023-45382] Improper Limitation of a Pathname to a Restricted Directory in Common-Services - SoNice Retour module for PrestaShop
In the module “SoNice Retour” (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack.
-
[CVE-2023-45387] Improper neutralization of SQL parameter in MyPrestaModules - Product Catalog (CSV, Excel, XML) Export PRO module for PrestaShop
In the module “Product Catalog (CSV, Excel, XML) Export PRO” (exportproducts) in versions up to 5.0.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection in affected versions.
-
Prestashop unremoved install directory risks
Prestashop installation directory must be deleted after a successful installation. It should not be renamed, as the remaining directory can contain code that is exploitable if publicly accessible, such as:
- tool to sync information in database
- tool to extract db information in xml files
-
[CVE-2023-43979] Improper neutralization of SQL parameter in PrestaHero (ETS Soft) - BLOG - Drive High Traffic & Boost SEO module for PrestaShop
In the module “BLOG - Drive High Traffic & Boost SEO” (ybc_blog) in version up to 3.3.8 from PrestaHero (ETS Soft) for PrestaShop, a guest can perform SQL injection in affected versions.
-
[CVE-2023-47309] Improper Neutralization of Input During Web Page Generation in Nukium - NKM GLS module for PrestaShop
In the module “NKM GLS” (nkmgls) up to version 3.0.1 from Nukium for PrestaShop, a guest (authenticated customer) can perform XSS injection of type 2 (stored XSS) from FRONT to BACK (F2B) of Category 2 within the funnel order in affected versions.
-
[CVE-2023-40923] Improper neutralization of an SQL parameter in MyPrestaModules - Orders (CSV, Excel) Export PRO module for PrestaShop
In the module “Orders (CSV, Excel) Export PRO” (ordersexport) from MyPrestaModules for PrestaShop, an anonymous user can perform SQL injection up to 5.0. Release 5.0 fixed this security issue.
-
[CVE-2023-47308] Improper neutralization of SQL parameter in Active Design - Newsletter Popup PRO with Voucher/Coupon code module for PrestaShop
In the module “Newsletter Popup PRO with Voucher/Coupon code” (newsletterpop) up to version 2.6.0 from Active Design for PrestaShop, a guest can perform SQL injection in affected versions.