Description
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete files from the server via the CustomerMessage API. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
Remediation
References
Related Vulnerabilities
e107 Other Vulnerability (CVE-2003-1191)
WordPress Resource Management Errors Vulnerability (CVE-2014-5266)
Moodle Other Vulnerability (CVE-2006-6625)
Plone CMS URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-1000484)
TYPO3 Cleartext Storage of Sensitive Information Vulnerability (CVE-2020-26228)