github.com
https://github.com/PrestaShop/PrestaShop CVE-2024-26129
MEDIUM
Prestashop vulnerable to path disclosure in JavaScript variable
Record summary
CVE-2024-26129 has a selected CVSS score of 5.8 (medium).
Description
PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure in a JavaScript variable. A patch is available in version 8.1.4.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 21, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
PrestaShopBrowse PrestaShop / PrestaShopDefault status: unknown | CVE List | >= 8.1.0, < 8.1.4 | affected |
| 8.1.0 to < 8.1.4 | affected | ||
prestashop/prestashopBrowse Packagist / prestashop/prestashop | GitHub Advisory | 8.1.0 to < 8.1.4 · Fixed in 8.1.4 | affected |
References
5github.com
https://github.com/PrestaShop/PrestaShop/commit/444bd0dea581659918fe2067541b9863cf099dd5 github.comConfirmation
https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-3366-9287-7qpr nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-26129 owasp.org
https://owasp.org/www-community/attacks/Full_Path_Disclosure