PT-2019-15880 · Prestashop · Prestashop
Andrea Iodice
·
Published
2019-12-05
·
Updated
2019-12-09
·
CVE-2019-19594
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PrestaShop versions 1.6 and 1.7
Description
The issue allows remote attackers to execute arbitrary code by uploading a .php file through the reset/modules/fotoliaFoto/multi upload.php endpoint in the RESET.PRO Adobe Stock API Integration.
Recommendations
For PrestaShop version 1.6, restrict access to the multi upload.php file to prevent arbitrary code execution.
For PrestaShop version 1.7, restrict access to the multi upload.php file to prevent arbitrary code execution.
Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prestashop