Arbitrary file read via SQL injection
High severity
GitHub Reviewed
Published
Apr 25, 2023
in
PrestaShop/PrestaShop
•
Updated Nov 11, 2023
Package
Affected versions
>= 8.0.0, < 8.0.4
< 1.7.8.9
Patched versions
8.0.4
1.7.8.9
Description
Published by the National Vulnerability Database
Apr 25, 2023
Published to the GitHub Advisory Database
Apr 26, 2023
Reviewed
Apr 26, 2023
Last updated
Nov 11, 2023
Impact
It is possible for a user having access to the SQL Manager (Advanced Options -> Database) to arbitrary read any file on the Operating system when using SQL function LOAD_FILE in a SELECT request. So It can access to critical information.
Patches
The patch will be on PS 8.0.4 and PS 1.7.8.9
References