PrestaShop blockreassurance BO User can remove any file from server when adding a and deleting a block
Moderate severity
GitHub Reviewed
Published
Nov 8, 2023
in
PrestaShop/blockreassurance
•
Updated Nov 9, 2023
Description
Published to the GitHub Advisory Database
Nov 8, 2023
Reviewed
Nov 8, 2023
Published by the National Vulnerability Database
Nov 8, 2023
Last updated
Nov 9, 2023
Impact
When adding a block in blockreassurance module, a BO user can modify the http request and give the path of any file in the project instead of an image. When deleting the block from the BO, the file will be deleted.
It is possible to make the website completely unavailable by removing index.php for example.
Patches
v5.1.4
Workarounds
No workaround available
References
References