PT-2022-8645 · Unknown · Prestashop
P1Nk15Amako
·
Published
2022-07-13
·
Updated
2022-07-25
·
CVE-2020-21967
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Prestashop version 1.7.6.7
Description
The issue allows remote attackers to run arbitrary code via the add new file page in the Catalog feature. This is a file upload vulnerability that can be exploited by attackers.
Recommendations
For Prestashop version 1.7.6.7, consider disabling the file upload feature in the Catalog until a patch is available to prevent remote attackers from running arbitrary code.
Exploit
Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prestashop