Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-19355

Опубликовано: 19 нояб. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Средний

Описание

modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a php file via modules/orderfiles/upload.php with auptype equal to product (for upload destinations under modules/productfiles), order (for upload destinations under modules/files), or cart (for upload destinations under modules/cartfiles).

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*
Версия от 1.5.0.0 (включая) до 1.7.0.0 (включая)
Конфигурация 2
cpe:2.3:a:mypresta:customer_files_upload:2018-08-01:*:*:*:*:prestashop:*:*

EPSS

Процентиль: 93%
0.11017
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a php file via modules/orderfiles/upload.php with auptype equal to product (for upload destinations under modules/productfiles), order (for upload destinations under modules/files), or cart (for upload destinations under modules/cartfiles).

EPSS

Процентиль: 93%
0.11017
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-434