Description
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, the `displayAjaxEmailHTML` method can be used to read any file on the server, potentially even outside of the project if the server is not correctly configured. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
Remediation
References
Related Vulnerabilities
WordPress Plugin Bug Library Cross-Site Scripting (2.0.3)
Contao Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-37626)
WordPress Plugin Visualizer:Tables and Charts Manager for WordPress PHAR Deserialization (3.7.9)
Oracle Application Server CVE-2008-1824 Vulnerability (CVE-2008-1824)