Description
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, the `displayAjaxEmailHTML` method can be used to read any file on the server, potentially even outside of the project if the server is not correctly configured. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
Remediation
References
Related Vulnerabilities
WordPress Plugin Events Made Easy Multiple Vulnerabilities (1.5.49)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-5876)
Ruby Use of Externally-Controlled Format String Vulnerability (CVE-2017-0898)
WordPress 4.7.x Cross-Site Request Forgery (4.7 - 4.7.12)
WordPress Plugin EZ Google Analytics Cross-Site Scripting (4.1.06)