Description PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to delete an image directory. Remediation References CVE-2018-19125 Related Vulnerabilities WordPress Plugin WP Symposium 'get_profile_avatar.php' SQL Injection (0.64) WordPress Ultimate Member Plugin URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-1209) Ruby Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2020-5247) osTicket Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-15362) XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29509) Severity High Classification CVE-2018-19125 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Tags Missing Update Known Vulnerabilities