Description
PrestaShop is an open-source e-commerce solution. Versions prior to 1.7.8.8 did not properly restrict host filesystem access for users. Users may have been able to view the contents of the upload directory without appropriate permissions. This issue has been addressed and users are advised to upgrade to version 1.7.8.8. There are no known workarounds for this issue.
Published: 2022-12-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-7588 PrestaShop is an open-source e-commerce solution. Versions prior to 1.7.8.8 did not properly restrict host filesystem access for users. Users may have been able to view the contents of the upload directory without appropriate permissions. This issue has been addressed and users are advised to upgrade to version 1.7.8.8. There are no known workarounds for this issue.
Github GHSA Github GHSA GHSA-9qgp-9wwc-v29r PrestaShop has potential Information exposure in the upload directory
History

Wed, 23 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Prestashop Prestashop
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-23T16:30:45.764Z

Reserved: 2022-11-28T17:27:19.997Z

Link: CVE-2022-46158

cve-icon Vulnrichment

Updated: 2024-08-03T14:24:03.395Z

cve-icon NVD

Status : Modified

Published: 2022-12-08T22:15:10.640

Modified: 2024-11-21T07:30:13.590

Link: CVE-2022-46158

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses