Description
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, the `displayAjaxEmailHTML` method can be used to read any file on the server, potentially even outside of the project if the server is not correctly configured. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
Remediation
References
Related Vulnerabilities
Sqlite Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2019-19646)
phpMyFAQ Sensitive Cookie in HTTPS Session Without 'Secure' Attribute Vulnerability (CVE-2023-5866)
WordPress Plugin Social Metrics Tracker Cross-Site Scripting (1.6.8)
WordPress Plugin WordPress OpenID Connect Client Cross-Site Scripting (2.1.4)