PT-2019-15880 · Prestashop · Prestashop

Andrea Iodice

·

Publicado

2019-12-05

·

Atualizado

2019-12-09

·

CVE-2019-19594

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PrestaShop versions 1.6 and 1.7
Description The issue allows remote attackers to execute arbitrary code by uploading a .php file through the reset/modules/fotoliaFoto/multi upload.php endpoint in the RESET.PRO Adobe Stock API Integration.
Recommendations For PrestaShop version 1.6, restrict access to the multi upload.php file to prevent arbitrary code execution. For PrestaShop version 1.7, restrict access to the multi upload.php file to prevent arbitrary code execution.

Exploit

Correção

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-19594

Produtos afetados

Prestashop