
Cloud Vulnerability DB
A community-led vulnerabilities database
A critical cross-site scripting (XSS) vulnerability (CVE-2024-34716) affects PrestaShop, an open-source e-commerce web application, from version 8.1.0 to versions prior to 8.1.6. The vulnerability specifically impacts installations with the customer-thread feature flag enabled through the front-office contact form (PrestaShop Advisory, NVD).
The vulnerability allows attackers to upload malicious files containing XSS payloads through the front-office contact form. When an administrator opens the attached file in the back office, the malicious script is executed. The executed script can access the administrator's session and security token, enabling unauthorized actions within the scope of administrator privileges. The vulnerability has received a CVSS v3.1 base score of 9.6 (Critical) from GitHub, Inc., with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H (PrestaShop Advisory).
The vulnerability enables attackers to potentially gain unauthorized access to the entire store's backend and sensitive information. When exploited, the attacker can perform any authenticated action within the administrator's privileges, potentially compromising the security and integrity of the entire PrestaShop installation (Security Online).
The vulnerability requires user interaction as it relies on an administrator opening the malicious file in the back office. The attack vector is network-accessible with low attack complexity and requires no privileges for exploitation (PrestaShop Advisory).
PrestaShop has released version 8.1.6 which includes patches for this vulnerability. For users unable to immediately upgrade, a temporary workaround is available by disabling the customer-thread feature-flag (PrestaShop Release, Security Online).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."