CVE-2013-6295
Prestashop vulnerability analysis and mitigation

Overview

CVE-2013-6295 is a privilege escalation vulnerability affecting PrestaShop version 1.5.5 and potentially prior versions. The vulnerability allowed users with Salesman or Logistician account privileges to upload malicious modules through the AdminModules functionality, potentially leading to unauthorized access to sensitive information and system compromise (Sopas Labs).

Technical details

The vulnerability exists in the module upload functionality within the AdminModulesController.php file. The code fails to properly validate uploaded files, allowing attackers to upload malicious PHP files disguised as legitimate modules. While the system checks for zip/tar files and folder structure, it does not properly validate the actual module contents, allowing arbitrary file uploads to the /modules/ directory (Sopas Labs).

Impact

The vulnerability allows lower-privileged users (Salesman/Logistician) to upload malicious PHP files that could expose sensitive information like database credentials, add unauthorized admin users, or potentially achieve server compromise through further exploitation. The attack could lead to complete system compromise if the server has additional vulnerabilities (Sopas Labs).

Mitigation and workarounds

PrestaShop addressed this vulnerability by changing the default profile permissions and removing the rights to add or delete modules from lower-privileged accounts. As a workaround, administrators are advised to remove module upload permissions from users who don't explicitly need this functionality and only grant it to trusted users (Sopas Labs).

Additional resources


SourceThis report was generated using AI

Related Prestashop vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61922CRITICAL9.1
  • PHPPHP
  • cpe:2.3:a:prestashop:prestashop
NoYesOct 16, 2025
CVE-2025-25692MEDIUM6.5
  • PrestashopPrestashop
  • cpe:2.3:a:prestashop:prestashop
NoNoJul 30, 2025
CVE-2025-61923MEDIUM4.1
  • PHPPHP
  • cpe:2.3:a:prestashop:prestashop
NoYesOct 16, 2025
CVE-2025-61924LOW3.8
  • PHPPHP
  • prestashop/ps_checkout
NoYesOct 16, 2025
CVE-2025-51586LOW3.7
  • PHPPHP
  • cpe:2.3:a:prestashop:prestashop
NoYesSep 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management