Attackers discover a zero day in PrestaShop that allows stealing the payment data of users of online stores. Vulnerability, now known by its CVE identifier 'CVE-2022-36408', enabled arbitrary code execution on servers hosting Prestashop websites that featured outdated versions of the software.  

The modus operandi so far has been similar.: The attackers exploited the flaw and, once obtained the ability to execute arbitrary code, injected non-legitimate payment forms to collect users' payment information.

From PrestaShop they claim to have located the vulnerability and that from the version 1.7.8.7 supposedly it had been fixed. However, they also stated that in the new versions of the software there are legacy features that are maintained for reasons of compatibility with previous versions and that could allow the existence of other ways to carry out the attack


Leave a Reply

Your email address will not be published. Required fields are marked *

More news
A cybercriminal manages to use AI to steal data from the Mexican Government
Read more »
Intec creates an AI that redefines the rules of the game in cybersecurity in the AI era.
Read more »
Una exfiltración de datos afecta a un proveedor de Adidas
Read more »
Se incrementan un 26% los incidentes de ciberseguridad
Read more »
Un ciberataque paraliza en Roma la Universidad La Sapienza
Read more »