← Vulnerability feed

Vulnerability record · CVE-2024-34716 · published 14 May 2024

CVE-2024-34716: PrestaShop customer-thread file upload XSS enables admin session theft

Prestashop · Prestashop

PrestaShop versions 8.1.0 through 8.1.5 with the customer-thread feature flag enabled allow an unauthenticated attacker to upload a file containing cross-site scripting through the front-office contact form. When an administrator opens the attachment in the back office, the script executes and can read the session and security token, letting the attacker act with the administrator's privileges. The flaw is patched in 8.1.6.

6.1 CVSS 3.1 Medium EPSS 56% · top 1.0% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting from PrestaShop 8.1.0 and prior to PrestaShop 8.1.6. When the customer thread feature flag is enabled through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office. The script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of the administrator's right. This vulnerability is patched in 8.1.6. A workaround is to disable the customer-thread feature-flag.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityThe vulnerability allows unauthenticated upload leading to admin session compromise, and the very high EPSS score indicates likely exploitation despite the medium CVSS rating.

What it is

PrestaShop versions 8.1.0 through 8.1.5 with the customer-thread feature flag enabled allow an unauthenticated attacker to upload a file containing cross-site scripting through the front-office contact form. When an administrator opens the attachment in the back office, the script executes and can read the session and security token, letting the attacker act with the administrator's privileges. The flaw is patched in 8.1.6.

Impact

An attacker gains the administrator's session and security token, enabling any authenticated action within the admin's rights, including full control of the store. This can lead to data theft, defacement, or further compromise of the e-commerce platform.

Attack surface

Reached remotely over the network through the front-office contact form when the customer-thread feature flag is enabled; no authentication is required for the upload, but the victim administrator must open the malicious attachment, so user interaction is needed.

Exploitation

Not listed in CISA KEV and no public exploit tags appear in the references, but EPSS is 0.56445 (99th percentile), indicating a high predicted likelihood of exploitation activity.

What to do

  • Upgrade PrestaShop to 8.1.6 or later immediately.
  • If immediate patching is not possible, disable the customer-thread feature flag as a temporary workaround.
  • Restrict or monitor file uploads through the front-office contact form until the patch is applied.
  • Review administrator accounts and sessions for signs of unauthorized activity after any suspected exposure.

Detection

  • Monitor web server and application logs for file uploads via the contact form that contain script content or unusual file types.
  • Alert on administrator sessions performing actions from unexpected IP addresses or user agents shortly after opening contact-form attachments.
  • Search for anomalous or unexpected files in upload directories associated with customer threads.
  • Review back-office access logs for suspicious admin actions following contact-form submissions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-34716 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-5791Prestashop vulnerabilityMultiple unspecified vulnerabilities in PrestaShop e-Commerce Solution before 1.1 Beta 2 (aka 1.1.0.1) have unknown impact and attack vectors, relate…EPSS 1.5%9.9CVE-2023-30838Prestashop cross-site scripting vulnerabilityPrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, the `ValidateCore::isCleanHTML()` method of Prestashop …EPSS 1.0%9.8CVE-2023-39526Prestashop sql injection vulnerabilityPrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through…EPSS 1.7%9.8CVE-2023-39524Prestashop sql injection vulnerabilityPrestaShop is an open source e-commerce web application. Prior to version 8.1.1, SQL injection possible in the product search field, in BO's product …EPSS 0.66%9.8CVE-2022-31181Prestashop injection vulnerabilityPrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerabilit…EPSS 6.6%9.8CVE-2022-21686Prestashop code injection vulnerabilityPrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig c…EPSS 1.8%9.8CVE-2021-43789Prestashop sql injection vulnerabilityPrestaShop is an Open Source e-commerce web application. Versions of PrestaShop prior to 1.7.8.2 are vulnerable to blind SQL injection using search f…EPSS 4.6%9.8CVE-2021-3110Prestashop sql injection vulnerabilityThe store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] p…EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2024-34716), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.