Server-Side Request Forgery (SSRF) in PrestaShop - #VU144203
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to perform server-side request forgery.
The vulnerability exists due to improper restriction of outbound requests in the back-office CSV import feature when processing image URLs from imported CSV files. A remote privileged user can supply a crafted CSV file with attacker-controlled image addresses to perform server-side request forgery.
The issue affects product imports and requires use of the back-office import feature.