PT-2018-10198 · Prestashop · Attribute Wizard+1

Publicado

2018-05-10

·

Atualizado

2018-06-13

·

CVE-2018-10942

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PrestaShop versions 1.4.0.1 through 1.6.1.18 Attribute Wizard addon version 1.6.9
Description The issue allows remote attackers to execute arbitrary code by uploading a .phtml file through the file upload.php in the Attribute Wizard addon.
Recommendations For PrestaShop versions 1.4.0.1 through 1.6.1.18, consider removing or restricting access to the file upload.php file in the Attribute Wizard addon until a patch is available. For Attribute Wizard addon version 1.6.9, restrict the upload of .phtml files to prevent arbitrary code execution.

Exploit

Correção

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10942

Produtos afetados

Attribute Wizard
Prestashop