CVE-2018-19355
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a php file via modules/orderfiles/upload.php with auptype equal to product (for upload destinations under modules/productfiles), order (for upload destinations under modules/files), or cart (for upload destinations under modules/cartfiles).
modules/orderfiles/ajax/upload.php en el addon Customer Files Upload 2018-08-01 para PrestaShop (de la versión 1.5 hasta la 1.7) permite que atacantes remotos ejecuten código arbitrario mediante la subida de un archivo php mediante modules/orderfiles/upload.php con auptype igual a product (para los destinos de subida en modules/productfiles), order (para los destinos de subida en modules/files) o cart (para los destinos de subida en modules/cartfiles).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-11-18 CVE Reserved
- 2018-11-19 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-09-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://ia-informatica.com/it/CVE-2018-19355 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Prestashop Search vendor "Prestashop" | Prestashop Search vendor "Prestashop" for product "Prestashop" | >= 1.5.0.0 <= 1.7.0.0 Search vendor "Prestashop" for product "Prestashop" and version " >= 1.5.0.0 <= 1.7.0.0" | - |
Affected
| ||||||
Mypresta Search vendor "Mypresta" | Customer Files Upload Search vendor "Mypresta" for product "Customer Files Upload" | 2018-08-01 Search vendor "Mypresta" for product "Customer Files Upload" and version "2018-08-01" | prestashop |
Affected
|