The Custom Product Designer (tshirtecommerce) module for PrestaShop allows HTTP requests to be forged using POST and GET parameters, enabling a remote attacker to perform directory traversal on the system and view the contents of code files.
id: CVE-2023-27639
info:
name: PrestaShop TshirteCommerce - Directory Traversal
author: MaStErC
...