CVE-2022-46158 MEDIUM

CVE-2022-46158: Potential Information exposure in the upload directory in PrestaShop

Vendor Prestashop
Product PrestaShop
Weakness CWE-200 · Info exposure
Published December 8, 2022
Last update April 23, 2025

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

PrestaShop is an open-source e-commerce solution. Versions prior to 1.7.8.8 did not properly restrict host filesystem access for users. Users may have been able to view the contents of the upload directory without appropriate permissions. This issue has been addressed and users are advised to upgrade to version 1.7.8.8. There are no known workarounds for this issue.

Key dates

02Disclosure timeline

December 8, 2022 CVE published
April 23, 2025 Record updated