Path Traversal in M4 PDF plugin for Prestashop sites
Vulnerability Description
M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to a directory traversal vulnerability. The “f” parameter is not properly checked in the resource /m4pdf/pdf.php, returning any file given its relative path. An attacker that exploits this vulnerability could download /etc/passwd from the server if the file exists.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-45447
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Francisco Díaz-Pache Alonso
- David Álvarez Robles
- Sergio Corral Cristo
Affected Vendor
Prestashop
View all reports →