Vulnerabilities > Prestashop

DATE CVE VULNERABILITY TITLE RISK
2018-03-28 CVE-2018-8823 Code Injection vulnerability in multiple products
modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute arbitrary PHP code via the code parameter.
network
low complexity
responsive-mega-menu-pro-project prestashop CWE-94
critical
9.8
2018-02-26 CVE-2018-7491 Improper Restriction of Rendered UI Layers or Frames vulnerability in Prestashop
In PrestaShop through 1.7.2.5, a UI-Redressing/Clickjacking vulnerability was found that might lead to state-changing impact in the context of a user or an admin, because the generateHtaccess function in classes/Tools.php sets neither X-Frame-Options nor 'Content-Security-Policy "frame-ancestors' values.
network
low complexity
prestashop CWE-1021
7.5
2018-01-13 CVE-2018-5682 Information Exposure vulnerability in Prestashop 1.7.2.4
PrestaShop 1.7.2.4 allows user enumeration via the Reset Password feature, by noticing which reset attempts do not produce a "This account does not exist" error message.
network
low complexity
prestashop CWE-200
5.3
2018-01-13 CVE-2018-5681 Cross-site Scripting vulnerability in Prestashop 1.7.2.4
PrestaShop 1.7.2.4 has XSS via source-code editing on the "Pages > Edit page" screen.
network
low complexity
prestashop CWE-79
5.4