PT-2020-7545 · Unknown · Prestashop
David Sopas
·
Published
2020-01-23
·
Updated
2020-02-06
·
CVE-2013-6358
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
PrestaShop version 1.5.5
Description:
The issue allows remote authenticated attackers to execute arbitrary code. This is achieved by uploading a crafted profile and then accessing it in the module/ directory.
Recommendations:
For PrestaShop version 1.5.5, consider restricting access to the module/ directory to prevent exploitation until a fix is available.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prestashop