Description
modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a php file via modules/orderfiles/upload.php with auptype equal to product (for upload destinations under modules/productfiles), order (for upload destinations under modules/files), or cart (for upload destinations under modules/cartfiles).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://ia-informatica.com/it/CVE-2018-19355 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:37:10.613Z
Reserved: 2018-11-18T00:00:00.000Z
Link: CVE-2018-19355
No data.
Status : Modified
Published: 2018-11-19T00:29:00.200
Modified: 2024-11-21T03:57:47.527
Link: CVE-2018-19355
No data.
OpenCVE Enrichment
No data.
Weaknesses