CVE-2023-27640 is a high-severity directory traversal vulnerability affecting the tshirtecommerce (Custom Product Designer) component 2.1.4 for PrestaShop. Attackers can forge an HTTP POST request to the /tshirtecommerce/fonts.php endpoint, using the 'type' parameter to read arbitrary files on the system, with the content returned in base64 encoding. This vulnerability has a CVSS score of 7.5 (HIGH) due to its network-based attack vector, low complexity, and high confidentiality impact, allowing unauthorized information disclosure. Crucially, this vulnerability is actively being exploited in the wild as of March 2023, despite a lack of public exploit code (Metasploit/ExploitDB) and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.1.4CPE matchmatch criteria | cpe:2.3:a:tshirtecommerce:custom_product_designer:*:*:*:*:*:prestashop:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.