E-Commerce
PrestaShop/PrestaShop
PrestaShop is the universal open-source software platform to build your e-commerce solution.
#prestashop#ecommerce#ecommerce-platform#cms#php#php-framework#ecommerce-framework#hacktoberfest
スコア
85
/ 100
Star
9,075
Fork
5,036
Open Issue
1,614
サイズ
771MB
言語
PHP ★
最終push
0 日前
Docker
🐳 compose ★
採点内訳
過去CVE 20件 (やや多い)
✓直近 push: 0 日前
✓得意言語 (PHP)
✓オープンissue 1614件
✓超大規模 (0.8GB)
—Docker 対応 (compose)
✓1k–10k: 初心者ベスト (★9,075)
✓※ 各項目の重みは「採点ルール」を参照。合計は 0 で底打ち。
過去の SecurityAdvisory (20 件)
- CWE-79: Stored XSS executable in customer service view
- CWE 79: Prevent multiple stored xss exploitation via unprotected variables in template
- Fix improper use of validation framework (CWE-1173)
- Time based enumeration in FO login form
- Email enumeration
- XSS via customer contact form in FO, through file upload
- Anonymous customer can download other customers's invoices
- Path disclosure in JavaScript variable
- XSS can be stored in DB from "add a message form" in order detail page (FO)
- Some attribute not escaped in Validate::isCleanHTML method
- Employee without any access rights can list all installed modules
- Uninstall modules from backoffice, even with low rights
- File deletion via CustomerMessage
- File deletion via attachment API
- Reading a file through path traversal
- New possible XSS injection through Validate::isCleanHTML method
- SQL manager vulnerability (potential RCE)
- path traversal: file deletion
- SQL injection possible in search product in BO
- SQL filter bypass leading to arbitrary write requests using "SQL Manager"