Executive brief
PrestaShop, a popular open-source e-commerce platform, contains a security vulnerability in its theme import feature. An attacker can exploit this flaw to execute unauthorized code on the server hosting the online store. This could lead to a full compromise of the website, including the theft of customer data or disruption of business operations.
Technical details
A PHAR (PHP Archive) deserialization vulnerability exists within the theme import functionality (/themes/import) of PrestaShop v8.2.0. The flaw is triggered when the application improperly handles untrusted data during a POST request, leading to insecure deserialization. An attacker can leverage this to achieve remote code execution (RCE) or command injection (CWE-77). The vulnerability is reachable over the network without requiring specific user interaction, though the CVSS assessment suggests limited impact on confidentiality and integrity despite the potential for code execution. A proof-of-concept exploit has been identified in third-party repositories.
Affected products
- PrestaShop PrestaShop 8.2.0
Timeline
- 2025-07-30: advisory: Initial NVD publication date