Description
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete files from the server via the CustomerMessage API. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
Remediation
References
Related Vulnerabilities
MediaWiki Insecure Storage of Sensitive Information Vulnerability (CVE-2021-36127)
Squid Improper Input Validation Vulnerability (CVE-2013-1839)
WordPress Plugin Integration for Contact Form 7 and Salesforce Cross-Site Scripting (1.2.4)
WordPress Plugin jQuery Mega Menu Widget 'skin' Parameter Local File Include (1.0)