S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Feb 2, 2024

CVE-2023-27639 Scanner

CVE-2023-27639 scanner - Directory Traversal vulnerability in The Custom Product Designer (tshirtecommerce) module for PrestaShop

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-27639
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter file_name in the tshirtecommerce/ajax.php?type=svg endpoint, to allow a remote attacker to traverse directories on the system in order to open files (without restriction on the extension and path). Only files that can be parsed in XML can be opened. This is exploited in the wild in March 2023.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 5, 2026View on NVD →
Detail

Navigating the Risks of PrestaShop's Custom Product Designer Vulnerability

Purpose and Use of Custom Product Designer Module for PrestaShop
The Custom Product Designer module, also known in the e-commerce space as "tshirtecommerce," is a vital asset for PrestaShop users. This tool empowers customers to customize products like t-shirts, mugs, and cards with their unique designs, adding images, text, and other graphical elements directly on the product pages. The popularity of this module stems from its ability to enhance user engagement and offer a personalized shopping experience, leading to increased satisfaction and sales for online merchants using the PrestaShop platform.

Understanding CVE-2023-27639
CVE-2023-27639 signifies a critical Directory Traversal vulnerability found in version 2.1.4 of the Custom Product Designer module for PrestaShop. Directory Traversal is a type of security exploit that allows attackers to access files and directories that are stored outside the web root folder. By exploiting such vulnerabilities, an attacker could potentially read sensitive files or execute malicious actions on the server, posing a significant threat to the security of an online store.

Consequences of the Directory Traversal Exploit
If malicious actors were to exploit the CVE-2023-27639 vulnerability within the Custom Product Designer module, the implications could be severe. Unauthorized access to critical system files, exposure of sensitive customer data, and the potential for broader network compromise are real dangers. Such breaches not only damage trust and reputation but can also have legal and financial repercussions for the store owners due to non-compliance with data protection regulations.

The Benefits of S4E for Your Cybersecurity Needs
For readers who are contemplating the cybersecurity posture of their digital assets, S4E offers robust Continuous Threat Exposure Management services. Their dedicated scanner, designed to detect vulnerabilities like CVE-2023-27639, exemplifies their commitment to security. By choosing S4E, you gain access to state-of-the-art tools that safeguard your business against evolving cyber threats, ensuring peace of mind and continuous operational resilience.

 

REFERENCES

Solution Advice

To mitigate risks associated with CVE-2023-27639, you must do the following:

  • Immediately update the Custom Product Designer module to the latest version that addresses this vulnerability.
  • Perform regular security audits of your website to ensure no other vulnerabilities are present.
  • Set up proper access controls and permissions to restrict file access on your server.
  • Employ a web application firewall (WAF) that can provide additional layers of security, including protection against common exploits.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.