PT-2018-10198 · Prestashop · Attribute Wizard+1

Published

2018-05-10

·

Updated

2018-06-13

·

CVE-2018-10942

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PrestaShop versions 1.4.0.1 through 1.6.1.18 Attribute Wizard addon version 1.6.9
Description The issue allows remote attackers to execute arbitrary code by uploading a .phtml file through the file upload.php in the Attribute Wizard addon.
Recommendations For PrestaShop versions 1.4.0.1 through 1.6.1.18, consider removing or restricting access to the file upload.php file in the Attribute Wizard addon until a patch is available. For Attribute Wizard addon version 1.6.9, restrict the upload of .phtml files to prevent arbitrary code execution.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10942

Affected Products

Attribute Wizard
Prestashop