peter bassill · operator
$ cve CVE-2024-34716 JSON

CVE-2024-34716

9.6
CRITICAL · CVSS 3.1 · EPSS 56.4% (pctl 99)

Patch early

EPSS 56.4% — above the 10% action threshold.

Description

PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting from PrestaShop 8.1.0 and prior to PrestaShop 8.1.6. When the customer thread feature flag is enabled through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office. The script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of the administrator's right. This vulnerability is patched in 8.1.6. A workaround is to disable the customer-thread feature-flag.

Scoring

CVSS9.6 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS56.45% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploitnone known
Published2024-05-14
Last modified2026-06-17

Affected (1)

VendorProduct
prestashopprestashop

References

→ the Explorer  ·  watch your stack  ·  NVD