Skip to content
E-commerce

Important security update for Prestashop

Team Host.it 3 min read

Content

A serious security problem affects some versions of Prestashop, it is therefore necessary to apply the patches made available by the international team to secure your e-commerce, let's see what the security problem is, which versions are affected and how to solve it without generating problems.

A vulnerability in the regeneration of users' passwords. The vulnerability concerns the methodology adopted for resetting users' passwords and therefore potentially also the store admin user. An attacker could therefore have access to the backend of your e-commerce site.

In detail, it would be possible to know the next randomly generated password that the shop will use to reset the next user who requests it.

The attack is not very simple to exploit but, as often fortunately happens, more detailed information on how the exploit is used has not been disclosed so that the impact on e-commerce is as small as possible, so you still have time to remedy it at the moment.

Versions affected by the vulnerability and patch application methods All versions of Prestashop, apart from the latest release 1.6.1.0, are affected by this security bug.

Specifically, the versions to be updated are therefore: 1.4.x, 1.5.x and 1.6.x up to 1.6.0.14.

I recommend two ways to update your ecommerce with Prestashop:

First method: installing the securitypatch module This is certainly the fastest method, download the module from the official Prestashop website and install it in your e-commerce on the backend side.

There is only one small precaution to take in this case, the installation of the securitypatch module uses a PHP function (exec) which is usually disabled for security reasons on most hosting platforms (this important rule also applies to us).

It is therefore necessary to ask your provider to enable it so that you can install it correctly. In our case you will just need to open a technical support ticket from our control panel https://cp.joomlahost.it

Second method: overwriting the files affected by the changes In case your provider does not want to activate the exec function of php (naughty eh) just to install the securitypatch module, it is still possible to apply the security patches by overwriting the affected files.

You can download the files from these official links on github, based on the versions you intend to update:

All you need to do is extract the zip you will download and upload it as it is to the root of your site in Prestashop.

Be careful because if you are aware that you have modified these files for your work needs, you will have to carry out a much more in-depth check. You will find useful instructions in the "Do it yourself" section of this official Prestashop patch page on github.

Conclusions Even in the summer period, webmasters and web agencies cannot sleep peacefully and must always be updated on important and useful news to live their business peacefully.

We at Colt Engine srl strongly believe in the role of the hosting provider as a "collaborator" of our customers' business, we have notified all our customers who use Prestashop via email and by writing this article, communicating how to update their ecommerce.

Was this article helpful or might it be helpful to someone you know? Share it on your social network and leave your opinion in the comments!

E-commerce

Hosting for online stores

PrestaShop, WooCommerce and Magento: performance, security and datacenters in Italy.

From the blog

E-commerce

Un’acquisizione strategica

Bhoost e Magentiamo in Host.it

From the archive

E-commerce

0-day vulnerability in PrestaShop

E-commerce

Cookie Policy and Cookie Bar, how to adapt your site