PrestaShop 1.7
Security and backups for the stores still on PrestaShop 1.7
Many stores still run PrestaShop 1.7, often with modules that cannot make the move to 8. They are also the versions hit by the 2022 attack.
The problem
1.7 releases before 1.7.8.7 were exposed.
In July 2022 an SQL injection hit PrestaShop from 1.6.0.10 onward: the fix came with 1.7.8.7. Attackers created blm.php in the root and inserted a fake payment form into the checkout.
We compare the installed version with the OSV.dev and Friends of Presta advisories: a 1.7 shop older than 1.7.8.7 gets a critical alert. Core integrity and the file scan find files already changed.
How it works
Tested on the three 1.7 minors.
- 1
Real installs
PrestaShop 1.7.6 with PHP 7.1 and 7.2, 1.7.7 with PHP 7.3, 1.7.8 with PHP 7.4.
- 2
Checks
Core integrity, malware signatures in templates and PHP, new administrators, installed modules, backup and restore.
- 3
Upgrades
Real upgrades with Update Assistant from 1.7.6 to 1.7.7, to 1.7.8 and to 8.0: one notification each.
In detail
In detail.
- A file like
blm.phpin the root shows up at the next scan - JavaScript loaders in Smarty templates, as in the 2026 skimmer
- Renamed admin folder recognised
- Encrypted backups of database and files on PHP 7.1
FAQ
Frequently asked questions
Does the module run on PHP 7.1?
Yes, on 1.7.6 it was tested with PHP 7.1 and 7.2.
Do you support PrestaShop 1.6?
No, the module starts at 1.7.6.
Related features
Goes well with
Try it on your clients' sites.
During the beta we let in a few agencies at a time and set up the first sites with you.