I'm just saying that the PS version has nothing to do.
For a hack to take place there are not 36 solutions:
- Theft of FTP credentials
- Unsecured module with upload functions
- Other unsecured CMS on the same hosting (8 obsolete WPs lately have infected PS)
Prestashop, since versions 1.2 has always controlled uploads and has never allowed direct access to these directories.
Regarding the rights, once a module is installed, regardless of whether it is 777, 755 or other, PHP can run create modify directories.