{"id":"CVE-2023-30545","summary":"PrestaShop arbitrary file read vulnerability","details":"PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, it is possible for a user with access to the SQL Manager (Advanced Options -\u003e Database) to arbitrarily read any file on the operating system when using SQL function `LOAD_FILE` in a `SELECT` request. This gives the user access to critical information. A patch is available in PrestaShop 8.0.4 and PS 1.7.8.9\n","aliases":["GHSA-8r4m-5p6p-52rp"],"modified":"2026-08-12T03:51:13.939370528Z","published":"2023-04-25T17:47:01.579Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/30xxx/CVE-2023-30545.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/30xxx/CVE-2023-30545.json"},{"type":"ADVISORY","url":"https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-8r4m-5p6p-52rp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-30545"},{"type":"FIX","url":"https://github.com/PrestaShop/PrestaShop/commit/cddac4198a47c602878a787280d813f60c6c0630"},{"type":"FIX","url":"https://github.com/PrestaShop/PrestaShop/commit/d900806e1841a31f26ff0a1843a6888fc1bb7f81"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/prestashop/prestashop","events":[{"introduced":"0"},{"fixed":"49d43b5fa0140304e64b530a5367cb30785eb15d"},{"introduced":"ca9d81aae0bb17f3e767bb5d835348ed144a3ab5"},{"fixed":"95d94dabaf40ba63be737b4a9cdbac328e66e5f9"},{"fixed":"cddac4198a47c602878a787280d813f60c6c0630"},{"fixed":"d900806e1841a31f26ff0a1843a6888fc1bb7f81"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.7.8.9"},{"introduced":"8.0.0"},{"fixed":"8.0.4"}]}}],"versions":["8.0.2","8.0.0-beta.1","1.7.8.3","1.7.0.0-rc.0.0","1.7.0.0-beta.4.0","1.7.0.0-beta.2.0","1.7.0.0-beta.1.0","1.6.1.0","1.6.0.3","1.6.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-30545.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}]}