PT-2018-10198 · Prestashop · Attribute Wizard+1
Published
2018-05-10
·
Updated
2018-06-13
·
CVE-2018-10942
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PrestaShop versions 1.4.0.1 through 1.6.1.18
Attribute Wizard addon version 1.6.9
Description
The issue allows remote attackers to execute arbitrary code by uploading a .phtml file through the
file upload.php in the Attribute Wizard addon.Recommendations
For PrestaShop versions 1.4.0.1 through 1.6.1.18, consider removing or restricting access to the
file upload.php file in the Attribute Wizard addon until a patch is available.
For Attribute Wizard addon version 1.6.9, restrict the upload of .phtml files to prevent arbitrary code execution.Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Attribute Wizard
Prestashop