Unknown · Prestashop · CVE-2020-21967
**Name of the Vulnerable Software and Affected Versions**
Prestashop version 1.7.6.7
**Description**
The issue allows remote attackers to run arbitrary code via the add new file page in the Catalog feature. This is a file upload vulnerability that can be exploited by attackers.
**Recommendations**
For Prestashop version 1.7.6.7, consider disabling the file upload feature in the Catalog until a patch is available to prevent remote attackers from running arbitrary code.