Threat Advisory

PrestaShop fixes bug that lets any Backend User Delete Databases

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

PrestaShop, an open-source e-commerce platform, has recently fixed a security bug that could have allowed any backend user to delete the website's databases. This vulnerability, tracked as CVE-2021-37668, affects versions 1.7.7.0 to 1.7.7.6 of PrestaShop and could potentially impact thousands of online stores. The security flaw was discovered and reported to PrestaShop by cybersecurity researcher. According to the report, the bug was caused by the platform's insufficient validation of user input, which allowed any authenticated backend user to execute arbitrary SQL queries on the website's database. By exploiting this vulnerability, an attacker could delete the entire database of a PrestaShop-powered website, which would result in a complete loss of all customer data, orders, and other critical information. This could have severe consequences for online businesses, potentially leading to financial losses and damage to their reputation.[/subscribe_to_unlock_form]

Summary:

PrestaShop, an open-source e-commerce platform, has recently fixed a security bug that could have allowed any backend user to delete the website's databases. This vulnerability, tracked as CVE-2021-37668, affects versions 1.7.7.0 to 1.7.7.6 of PrestaShop and could potentially impact thousands of online stores. The security flaw was discovered and reported to PrestaShop by cybersecurity researcher. According to the report, the bug was caused by the platform's insufficient validation of user input, which allowed any authenticated backend user to execute arbitrary SQL queries on the website's database. By exploiting this vulnerability, an attacker could delete the entire database of a PrestaShop-powered website, which would result in a complete loss of all customer data, orders, and other critical information. This could have severe consequences for online businesses, potentially leading to financial losses and damage to their reputation.[emaillocker id="1283"]

Fortunately, PrestaShop acted swiftly to address the issue by releasing a security patch that fixes the vulnerability. The patch has been made available to all affected versions of the platform, and website owners are strongly advised to update their installations as soon as possible to avoid any potential security incidents. This incident highlights the importance of regular security audits and updates to e-commerce platforms, as well as the need for proper security controls and user input validation to prevent potential attacks. As online businesses continue to grow and rely more on e-commerce platforms, ensuring their security and integrity becomes paramount to protecting customer data and maintaining trust.

Recommendations:

We strongly recommend that you update PrestaShop to version 8.0.4 and 1.7.8.9

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/prestashop-fixes-bug-that-lets-any-backend-user-delete-databases/

[/emaillocker]
crossmenu