PT-2019-15880 · Prestashop · Prestashop
Andrea Iodice
·
Publicado
2019-12-05
·
Atualizado
2019-12-09
·
CVE-2019-19594
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PrestaShop versions 1.6 and 1.7
Description
The issue allows remote attackers to execute arbitrary code by uploading a .php file through the reset/modules/fotoliaFoto/multi upload.php endpoint in the RESET.PRO Adobe Stock API Integration.
Recommendations
For PrestaShop version 1.6, restrict access to the multi upload.php file to prevent arbitrary code execution.
For PrestaShop version 1.7, restrict access to the multi upload.php file to prevent arbitrary code execution.
Exploit
Correção
RCE
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Prestashop