PT-2022-8645 · Unknown · Prestashop

P1Nk15Amako

·

Published

2022-07-13

·

Updated

2022-07-25

·

CVE-2020-21967

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Prestashop version 1.7.6.7
Description The issue allows remote attackers to run arbitrary code via the add new file page in the Catalog feature. This is a file upload vulnerability that can be exploited by attackers.
Recommendations For Prestashop version 1.7.6.7, consider disabling the file upload feature in the Catalog until a patch is available to prevent remote attackers from running arbitrary code.

Exploit

Fix

RCE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-21967

Affected Products

Prestashop