Description
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, the `displayAjaxEmailHTML` method can be used to read any file on the server, potentially even outside of the project if the server is not correctly configured. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
Remediation
References
Related Vulnerabilities
MySQL CVE-2015-2567 Vulnerability (CVE-2015-2567)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17306)
WordPress Plugin IMPress for IDX Broker Unspecified Vulnerability (2.5.11)
WordPress Plugin Top 10-Popular posts for WordPress Multiple Vulnerabilities (3.2.3)