CVE-2023-27639 is a directory traversal vulnerability affecting the tshirtecommerce (Custom Product Designer) component 2.1.4 for PrestaShop. An unauthenticated attacker can forge an HTTP request to the ajax.php?type=svg endpoint, using the file_name POST parameter, to read arbitrary XML-parsable files on the system. This vulnerability has a CVSS score of 7.5 (High), indicating a network-exploitable, low-complexity attack with high confidentiality impact. Crucially, this vulnerability is being actively exploited in the wild as of March 2023, with Nuclei templates available for detection. Despite active exploitation, there is no public Metasploit or ExploitDB code, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.1.4CPE matchmatch criteria | cpe:2.3:a:tshirtecommerce:custom_product_designer:*:*:*:*:*:prestashop:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.