Aller au contenu

Fiche vulnérabilité

CVE-2023-27640 : faille élevée tshirtecommerce custom product designer (CVSS 7.5)

Description

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter type in the /tshirtecommerce/fonts.php endpoint, to allow a remote attacker to traverse directories on the system in order to open files (without restriction on the extension and path). The content of the file is returned with base64 encoding. This is exploited in the wild in March 2023.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
1 juin 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • tshirtecommerce custom product designer

Références

Rechercher une autre vulnérabilité dans la base CVE