CVE-2023-27639 | tshirtecommerce 2.1.4 on PrestaShop POST Parameter ajax.php?type=svg file_name path traversal
A vulnerability has been found in tshirtecommerce 2.1.4 on PrestaShop and classified as critical. This vulnerability affects unknown code of the file tshirtecommerce/ajax.php?type=svg of the component POST Parameter Handler. The manipulation of the argument file_name leads to path traversal.
This vulnerability was named CVE-2023-27639. The attack can be initiated remotely. Furthermore, there is an exploit available.