PT-2024-20348 · Prestashop · Prestashop Product Designer Module

Published

2024-03-03

·

Updated

2024-08-08

·

CVE-2024-24307

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PrestaShop Product Designer module versions prior to 1.178.36
Description The issue allows a remote attacker to escalate privileges and obtain sensitive information. This is achieved via the ajaxProcessCropImage() method.
Recommendations For versions prior to 1.178.36, update to version 1.178.36 or later to resolve the issue. As a temporary workaround, consider disabling the ajaxProcessCropImage() method until a patch is available.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-24307

Affected Products

Prestashop Product Designer Module