PT-2018-10198 · Prestashop · Attribute Wizard+1
Publicado
2018-05-10
·
Atualizado
2018-06-13
·
CVE-2018-10942
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PrestaShop versions 1.4.0.1 through 1.6.1.18
Attribute Wizard addon version 1.6.9
Description
The issue allows remote attackers to execute arbitrary code by uploading a .phtml file through the
file upload.php in the Attribute Wizard addon.Recommendations
For PrestaShop versions 1.4.0.1 through 1.6.1.18, consider removing or restricting access to the
file upload.php file in the Attribute Wizard addon until a patch is available.
For Attribute Wizard addon version 1.6.9, restrict the upload of .phtml files to prevent arbitrary code execution.Exploit
Correção
RCE
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Attribute Wizard
Prestashop