CVE-2023-27640

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jun 1, 2023
Updated: Jan 8, 2025
CWE ID 22

Summary

CVE-2023-27640 is a vulnerability affecting the tshirtecommerce component 2.1.4 of PrestaShop. This issue enables an attacker to forge an HTTP request, manipulating the POST parameter type in the /tshirtecommerce/fonts.php endpoint. By doing so, they can traverse directories on the system and access files, unrestricted in terms of extension and path. These files are then returned with base64 encoding. This vulnerability was exploited in the wild in March 2023.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share