matthieu-rolland
6 exploits
Active since Aug 2023
PrestaShop <1.7.8.10, 8.0.5, <8.1.1 - Remote Code Execution via SQL Injection and Arbitrary File Write
CVSS 9.1
PrestaShop < 8.1.1 - SQL Injection via Product Search Field
CVSS 6.7
PrestaShop < 8.1.1 - Path Traversal via Import File Deletion Query
CVSS 6.5
PrestaShop < 1.7.8.10, 8.0.5, 8.1.1 - Cross-Site Scripting via isCleanHTML Method
CVSS 8.3
PrestaShop < 8.1.1 - Path Traversal via displayAjaxEmailHTML Method
CVSS 6.8
PrestaShop < 8.1.2 - Improper Privilege Management via Module Disabling
CVSS 6.3