Moderate severityNVD Advisory· Published Feb 19, 2024· Updated Aug 1, 2024
Prestashop vulnerable to path disclosure in JavaScript variable
CVE-2024-26129
Description
PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure in a JavaScript variable. A patch is available in version 8.1.4.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
prestashop/prestashopPackagist | >= 8.1.0, < 8.1.4 | 8.1.4 |
Affected products
1- Range: >= 8.1.0, < 8.1.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/advisories/GHSA-3366-9287-7qprghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-26129ghsaADVISORY
- github.com/PrestaShop/PrestaShop/commit/444bd0dea581659918fe2067541b9863cf099dd5ghsax_refsource_MISCWEB
- github.com/PrestaShop/PrestaShop/security/advisories/GHSA-3366-9287-7qprghsax_refsource_CONFIRMWEB
- owasp.org/www-community/attacks/Full_Path_Disclosureghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.