Description
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete a file from the server by using the Attachments controller and the Attachments API. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
Remediation
References
Related Vulnerabilities
WordPress Plugin Music Store Cross-Site Scripting (1.0.41)
Joomla! Core Remote Code Execution (1.5.0 - 3.4.5)
PHP Numeric Errors Vulnerability (CVE-2016-4346)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-5268)
PrestaShop Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-19594)