{"id":"CVE-2024-34716","aliases":["GHSA-45vm-3j38-7p78"],"url":"https://o3.security/vulnerability/CVE-2024-34716","summary":"PrestaShop vulnerable to XSS via customer contact form in FO, through file upload","details":"### Impact\nOnly PrestaShops with customer-thread feature flag enabled are impacted, starting from PrestaShop 8.1.0.\n\nThe impact is substantial, when the customer thread feature flag is enabled, through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office.\n\nConsequence: the script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of the administrator's right.\n\n### Patches\nThis vulnerability is patched in 8.1.6.\n\n### Workarounds\nAs long as you have not upgraded to 8.1.6, a simple workaround is to disable the customer-thread feature-flag.\n\nThank you to Ayoub AIT ELMOKHTAR, who discovered this vulnerability and share it with the PrestaShop team.\n","published":"2024-05-14T15:45:45.345Z","modified":"2026-08-12T03:51:09.161283393Z","cvss":{"score":9.6,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Packagist","name":"prestashop/prestashop","fixedVersion":"8.1.6"}],"fix":{"url":"https://github.com/PrestaShop/PrestaShop/commit/a248898655e56cbcc6c308a5f1c8752231624bae","label":"PrestaShop/PrestaShop@a248898"},"references":[{"type":"WEB","url":"https://github.com/PrestaShop/PrestaShop/releases/tag/8.1.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/34xxx/CVE-2024-34716.json"},{"type":"ADVISORY","url":"https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-45vm-3j38-7p78"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34716"},{"type":"WEB","url":"https://github.com/PrestaShop/PrestaShop/commit/a248898655e56cbcc6c308a5f1c8752231624bae"},{"type":"PACKAGE","url":"https://github.com/PrestaShop/PrestaShop"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:09.161283393Z"}}