Description
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete files from the server via the CustomerMessage API. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
Remediation
References
Related Vulnerabilities
MySQL CVE-2014-0384 Vulnerability (CVE-2014-0384)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1000862)
MySQL CVE-2019-2687 Vulnerability (CVE-2019-2687)
Claroline Other Vulnerability (CVE-2005-1376)
WordPress Plugin Web to Print Online Designer Security Bypass (2.3.0)