Skip to content

GHSA-xrwj-pq6w-f8m4 GHSA-w6j9-q9rq-wrqg GHSA-2cr4-vw9p-pjvf GHSA-whxq-pxj5-qq7v GHSA-jf3w-9rmr-5rcr

PrestaShop 9.1.5 and 8.2.8 fix SSRF, SQL injection and access control flaws

High 8.2 Vendor: PrestaShop Published

PrestaShop 9.0.0 to before 9.1.5 and 8.0.0 to before 8.2.8 are affected by five security advisories: SSRF, CSV injection, IP spoofing, SQL injection and broken access control. Upgrade to PrestaShop 9.1.5 or 8.2.8.

What happened

PrestaShop has published five GitHub security advisories fixed in the 9.1.5 and 8.2.8 releases. The highest-rated issue is a server-side request forgery in the CSV import feature: a back-office employee with import permission can point the shop at arbitrary image URLs, and the server will fetch them. PrestaShop notes this can escalate to arbitrary code and rates the issue high at CVSS 8.2.

That release also fixes an SQL injection in back-office list filters. A logged-in employee could submit a crafted filter name to run a query of their own choosing, reading data across the database, including employee password hashes and customer and order tables. The reporter demonstrated it with the most restricted built-in profile. Separately, a flaw in how PrestaShop reads the X-Forwarded-For header lets an unauthenticated visitor spoof their IP address when the shop sits behind a reverse proxy, load balancer or CDN, bypassing maintenance-mode allow-lists, forging logs, or evading geolocation, fraud-scoring and rate-limiting controls.

A further two advisories cover CSV formula injection in exported files, which can affect whoever opens an export in a spreadsheet, and missing authorisation on the back-office notifications endpoint, which exposes customer names, order totals, carrier and order status to any employee account. None of the advisories reports active exploitation.

Who is affected

These advisories apply to PrestaShop 9.0.0 to before 9.1.5 and 8.0.0 to before 8.2.8. For SQL injection, PrestaShop states the flawed legacy back-office controller is also present in 1.7.x and earlier, which are end of life and will not receive a patch. The X-Forwarded-For issue affects shops served through a reverse proxy, load balancer or CDN; PrestaShop says this covers most production deployments, while direct-to-web-server installations are not affected. The back-office issues require a valid employee account; the notifications flaw is reachable by any logged-in employee, including profiles with no permissions.

What to do now

  1. Upgrade to PrestaShop 9.1.5 or 8.2.8. These are the fixed versions for all five advisories.
  2. For the CSV import SSRF, also restrict the import permission to profiles that genuinely need it and only import from trusted sources. Filter outbound traffic so the web server cannot reach your private network or cloud metadata service.
  3. For the X-Forwarded-For issue, configure your front-end proxy to overwrite the forwarding header with the address it actually sees, even after upgrading. PrestaShop provides Nginx and Apache examples; CDN users should ensure the origin only accepts connections from the CDN's address ranges.
  4. For CSV injection, train staff to open exports via the spreadsheet import wizard with all columns set to text, and inspect any cell beginning with =, +, - or @ before exporting. SQL injection and the notifications access-control issue have no configuration workarounds.

Beyond the patch

These flaws cluster around a public e-commerce platform where back-office permissions, proxy handling, and vendor patch cadence all matter. A penetration test or hardening review under Implementation & Assessment Services can confirm the upgrade actually closed the paths in your deployment, while Supply Chain Defense & Third-Party Risk helps you track which PrestaShop versions you run and how quickly vendor fixes reach your estate.

Affected and fixed versions

ProductAffectedFixed in
GHSA-xrwj-pq6w-f8m4, GHSA-w6j9-q9rq-wrqg, GHSA-2cr4-vw9p-pjvf, GHSA-whxq-pxj5-qq7v, GHSA-jf3w-9rmr-5rcr
PrestaShop
9.0.0 – < 9.1.5
8.0.0 – < 8.2.8
9.1.5
8.2.8
.5

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them. Entries marked GHSA have no CVE: their source is the security advisory the maintainers published in their official GitHub repository.

Written with AI assistance from the sources above and checked automatically against them before publication.