GHSA-xrwj-pq6w-f8m4 GHSA-w6j9-q9rq-wrqg GHSA-2cr4-vw9p-pjvf GHSA-whxq-pxj5-qq7v GHSA-jf3w-9rmr-5rcr
PrestaShop 9.1.5 and 8.2.8 fix SSRF, SQL injection and access control flaws
PrestaShop 9.0.0 to before 9.1.5 and 8.0.0 to before 8.2.8 are affected by five security advisories: SSRF, CSV injection, IP spoofing, SQL injection and broken access control. Upgrade to PrestaShop 9.1.5 or 8.2.8.
What happened
PrestaShop has published five GitHub security advisories fixed in the 9.1.5 and 8.2.8 releases. The highest-rated issue is a server-side request forgery in the CSV import feature: a back-office employee with import permission can point the shop at arbitrary image URLs, and the server will fetch them. PrestaShop notes this can escalate to arbitrary code and rates the issue high at CVSS 8.2.
That release also fixes an SQL injection in back-office list filters. A logged-in employee could submit a crafted filter name to run a query of their own choosing, reading data across the database, including employee password hashes and customer and order tables. The reporter demonstrated it with the most restricted built-in profile. Separately, a flaw in how PrestaShop reads the X-Forwarded-For header lets an unauthenticated visitor spoof their IP address when the shop sits behind a reverse proxy, load balancer or CDN, bypassing maintenance-mode allow-lists, forging logs, or evading geolocation, fraud-scoring and rate-limiting controls.
A further two advisories cover CSV formula injection in exported files, which can affect whoever opens an export in a spreadsheet, and missing authorisation on the back-office notifications endpoint, which exposes customer names, order totals, carrier and order status to any employee account. None of the advisories reports active exploitation.
Who is affected
These advisories apply to PrestaShop 9.0.0 to before 9.1.5 and 8.0.0 to before 8.2.8. For SQL injection, PrestaShop states the flawed legacy back-office controller is also present in 1.7.x and earlier, which are end of life and will not receive a patch. The X-Forwarded-For issue affects shops served through a reverse proxy, load balancer or CDN; PrestaShop says this covers most production deployments, while direct-to-web-server installations are not affected. The back-office issues require a valid employee account; the notifications flaw is reachable by any logged-in employee, including profiles with no permissions.
What to do now
- Upgrade to PrestaShop 9.1.5 or 8.2.8. These are the fixed versions for all five advisories.
- For the CSV import SSRF, also restrict the import permission to profiles that genuinely need it and only import from trusted sources. Filter outbound traffic so the web server cannot reach your private network or cloud metadata service.
- For the X-Forwarded-For issue, configure your front-end proxy to overwrite the forwarding header with the address it actually sees, even after upgrading. PrestaShop provides Nginx and Apache examples; CDN users should ensure the origin only accepts connections from the CDN's address ranges.
- For CSV injection, train staff to open exports via the spreadsheet import wizard with all columns set to text, and inspect any cell beginning with =, +, - or @ before exporting. SQL injection and the notifications access-control issue have no configuration workarounds.
Beyond the patch
These flaws cluster around a public e-commerce platform where back-office permissions, proxy handling, and vendor patch cadence all matter. A penetration test or hardening review under Implementation & Assessment Services can confirm the upgrade actually closed the paths in your deployment, while Supply Chain Defense & Third-Party Risk helps you track which PrestaShop versions you run and how quickly vendor fixes reach your estate.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| GHSA-xrwj-pq6w-f8m4, GHSA-w6j9-q9rq-wrqg, GHSA-2cr4-vw9p-pjvf, GHSA-whxq-pxj5-qq7v, GHSA-jf3w-9rmr-5rcr PrestaShop | 9.0.0 – < 9.1.5 8.0.0 – < 8.2.8 | 9.1.5 8.2.8 .5 |
References
Vendor advisory
- Server-Side Request Forgery through image URLs in the CSV import
- Formula injection in CSV exports (CSV injection)
- Client IP address can be spoofed through the X-Forwarded-For header
- SQL injection through back-office list filters
- Improper access control on the back-office notifications endpoint exposes customer data