PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure in a JavaScript variable. A patch is available in version 8.1.4.
https://owasp.org/www-community/attacks/Full_Path_Disclosure
https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-3366-9287-7qpr
https://github.com/PrestaShop/PrestaShop/commit/444bd0dea581659918fe2067541b9863cf099dd5
Published: 2024-02-19
Updated: 2025-01-17
Named Vulnerability: Path disclosure in JavaScript variable
Base Score: 5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N
Severity: Medium
Base Score: 5.3
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity: Medium
EPSS: 0.00265