Description
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete files from the server via the CustomerMessage API. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
Remediation
References
Related Vulnerabilities
OpenSSL Other Vulnerability (CVE-2003-0851)
WordPress Plugin DosCero.Menu Cross-Site Scripting (1.0)
WordPress Plugin Members Import Cross-Site Request Forgery (1.3)
WordPress Plugin Image Gallery-Responsive Photo Gallery Cross-Site Scripting (1.4.0)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-5487)