Description
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, it is possible to delete files from the server via the CustomerMessage API. Version 8.1.1 contains a patch for this issue. There are no known workarounds.
Remediation
References
Related Vulnerabilities
WordPress Plugin RapidLoad Power-Up for Autoptimize Multiple Vulnerabilities (1.7.1)
WordPress Plugin Estatik Real Estate Cross-Site Request Forgery (3.8.3)
WordPress Plugin Relevanssi Premium-A Better Search Cross-Site Scripting (1.14.8)
WordPress Plugin Easy Property Listings Cross-Site Scripting (3.3.5.8)
Apache Traffic Server CVE-2014-3525 Vulnerability (CVE-2014-3525)