Vulnerability record · CVE-2024-34716 · published 14 May 2024
CVE-2024-34716: PrestaShop customer-thread file upload XSS enables admin session theft
Prestashop · Prestashop
PrestaShop versions 8.1.0 through 8.1.5 with the customer-thread feature flag enabled allow an unauthenticated attacker to upload a file containing cross-site scripting through the front-office contact form. When an administrator opens the attachment in the back office, the script executes and can read the session and security token, letting the attacker act with the administrator's privileges. The flaw is patched in 8.1.6.
Description
PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting from PrestaShop 8.1.0 and prior to PrestaShop 8.1.6. When the customer thread feature flag is enabled through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office. The script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of the administrator's right. This vulnerability is patched in 8.1.6. A workaround is to disable the customer-thread feature-flag.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityThe vulnerability allows unauthenticated upload leading to admin session compromise, and the very high EPSS score indicates likely exploitation despite the medium CVSS rating.
What it is
PrestaShop versions 8.1.0 through 8.1.5 with the customer-thread feature flag enabled allow an unauthenticated attacker to upload a file containing cross-site scripting through the front-office contact form. When an administrator opens the attachment in the back office, the script executes and can read the session and security token, letting the attacker act with the administrator's privileges. The flaw is patched in 8.1.6.
Impact
An attacker gains the administrator's session and security token, enabling any authenticated action within the admin's rights, including full control of the store. This can lead to data theft, defacement, or further compromise of the e-commerce platform.
Attack surface
Reached remotely over the network through the front-office contact form when the customer-thread feature flag is enabled; no authentication is required for the upload, but the victim administrator must open the malicious attachment, so user interaction is needed.
Exploitation
Not listed in CISA KEV and no public exploit tags appear in the references, but EPSS is 0.56445 (99th percentile), indicating a high predicted likelihood of exploitation activity.
What to do
- Upgrade PrestaShop to 8.1.6 or later immediately.
- If immediate patching is not possible, disable the customer-thread feature flag as a temporary workaround.
- Restrict or monitor file uploads through the front-office contact form until the patch is applied.
- Review administrator accounts and sessions for signs of unauthorized activity after any suspected exposure.
Detection
- Monitor web server and application logs for file uploads via the contact form that contain script content or unusual file types.
- Alert on administrator sessions performing actions from unexpected IP addresses or user agents shortly after opening contact-form attachments.
- Search for anomalous or unexpected files in upload directories associated with customer threads.
- Review back-office access logs for suspicious admin actions following contact-form submissions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/PrestaShop/PrestaShop/releases/tag/8.1.6 | Release Notes |
| https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-45vm-3j38-7p78 | Vendor Advisory |
| https://github.com/PrestaShop/PrestaShop/releases/tag/8.1.6 | Release Notes |
| https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-45vm-3j38-7p78 | Vendor Advisory |
Track CVE-2024-34716 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-34716), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.