Информация Prestashop Security

  • Автор темы

Major Security Vulnerability On PrestaShop Websites​

A NEWLY FOUND EXPLOIT COULD ALLOW REMOTE ATTACKERS TO TAKE CONTROL OF YOUR SHOP.​

Written by
PrestaShop team

Published
Jul 22, 2022

Для просмотра ссылки Войди или Зарегистрируйся
Вам ещё нужны аргументы, чтобы обновиться наконец ?

И не думайте, что ваш сайт никому не нужен...

Рашисты и другие недоброжелатели - не спят, и любой сайт или сервер можно использовать для своих тёмных делишек
 
Уязвимость в Advanced Popup Creator (advancedpopupcreator) module
Для просмотра ссылки Войди или Зарегистрируйся

Patch​

The issue was fixed by sanitizing $controller using pSQL:)(

PHP:
- OR FIND_IN_SET("' . $controller . '", `controller_exceptions`))';
+ OR FIND_IN_SET("' . pSQL($controller) . '", `controller_exceptions`))';


Applied at two different places in the code:

  • Line ~371
  • Line ~986
Fixed version: 1.2.7
 
срочно обновляемся
Обновление безопасности для модуля фасетного поиска (ps_facetedsearch)

You are receiving this security communication just before we send it to the wider merchant community. As a member of PrestaShop tech community, you are often the first person your clients turn to when something like this lands, so we want you prepared before the messages start coming in.

What we discovered

We have identified a critical vulnerability in the Faceted Search module (ps_facetedsearch), which powers product filtering on a large share of stores. We’ve just released a new version that fixes it, and we will shortly ask merchants to update without delay.

Because this module is so widely installed, the population of affected stores is significant. Any store using ps_facetedsearch should be treated as exposed until it is updated.

Alongside this, the merchant email will include a reminder about the recent core security releases on the 8.2 and 9.1 branches (8.2.6 and 9.1.1), which fixed a separate critical vulnerability. Both matter, but the Faceted Search update is the new one, and the one we want you focused on first.
Для просмотра ссылки Войди или Зарегистрируйся============================================================================================
[CVE-2026-39079] Sensitive data exposure via publicly accessible logs in upsshipping module from Agence Web 360 for PrestaShop
временное решение Для просмотра ссылки Войди или Зарегистрируйся
 
Назад
Сверху