PT-2019-15880 · Prestashop · Prestashop

Andrea Iodice

·

Published

2019-12-05

·

Updated

2019-12-09

·

CVE-2019-19594

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PrestaShop versions 1.6 and 1.7
Description The issue allows remote attackers to execute arbitrary code by uploading a .php file through the reset/modules/fotoliaFoto/multi upload.php endpoint in the RESET.PRO Adobe Stock API Integration.
Recommendations For PrestaShop version 1.6, restrict access to the multi upload.php file to prevent arbitrary code execution. For PrestaShop version 1.7, restrict access to the multi upload.php file to prevent arbitrary code execution.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19594

Affected Products

Prestashop