CVE-2024-34716
PHP vulnerability analysis and mitigation

Overview

A critical cross-site scripting (XSS) vulnerability (CVE-2024-34716) affects PrestaShop, an open-source e-commerce web application, from version 8.1.0 to versions prior to 8.1.6. The vulnerability specifically impacts installations with the customer-thread feature flag enabled through the front-office contact form (PrestaShop Advisory, NVD).

Technical details

The vulnerability allows attackers to upload malicious files containing XSS payloads through the front-office contact form. When an administrator opens the attached file in the back office, the malicious script is executed. The executed script can access the administrator's session and security token, enabling unauthorized actions within the scope of administrator privileges. The vulnerability has received a CVSS v3.1 base score of 9.6 (Critical) from GitHub, Inc., with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H (PrestaShop Advisory).

Impact

The vulnerability enables attackers to potentially gain unauthorized access to the entire store's backend and sensitive information. When exploited, the attacker can perform any authenticated action within the administrator's privileges, potentially compromising the security and integrity of the entire PrestaShop installation (Security Online).

Exploitability

The vulnerability requires user interaction as it relies on an administrator opening the malicious file in the back office. The attack vector is network-accessible with low attack complexity and requires no privileges for exploitation (PrestaShop Advisory).

Mitigation and workarounds

PrestaShop has released version 8.1.6 which includes patches for this vulnerability. For users unable to immediately upgrade, a temporary workaround is available by disabling the customer-thread feature-flag (PrestaShop Release, Security Online).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47156CRITICAL9.3
  • PHP logoPHP
  • mantisbt/mantisbt
NoYesSep 09, 2026
CVE-2026-85400HIGH7.5
  • PHP logoPHP
  • cpe:2.3:a:typo3:typo3
NoYesSep 08, 2026
CVE-2026-53637MEDIUM6.5
  • PHP logoPHP
  • sylius/sylius
NoYesSep 08, 2026
CVE-2026-53639MEDIUM6.3
  • PHP logoPHP
  • sylius/sylius
NoYesSep 08, 2026
CVE-2026-53638MEDIUM4.3
  • PHP logoPHP
  • sylius/sylius
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management