Description
PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability which can be chained to call PHP's Eval function on attacker input. The problem is fixed in version 1.7.8.7. Users are advised to upgrade. Users unable to upgrade may delete the MySQL Smarty cache feature.
Remediation
References
Related Vulnerabilities
Jenkins 7PK - Security Features Vulnerability (CVE-2014-9635)
WordPress Plugin Bulk change of posts terms and post types Cross-Site Scripting (1.0)
Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-33331)
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2212)