CVE-2018-20717
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
In the orders section of PrestaShop before 1.7.2.5, an attack is possible after gaining access to a target store with a user role with the rights of at least a Salesman or higher privileges. The attacker can then inject arbitrary PHP objects into the process and abuse an object chain in order to gain Remote Code Execution. This occurs because protection against serialized objects looks for a 0: followed by an integer, but does not consider 0:+ followed by an integer.
En la sección de pedidos de PrestaShop, en versiones anteriores a la 1.7.2.5, es posible un ataque tras obtener acceso a una tienda objetivo con un rol de usuario con derechos de, al menos, "Salesman" o superiores. El atacante puede inyectar objetos PHP arbitrarios en el proceso y abusar de una cadena de objetos para poder ejecutar código de forma remota. Esto ocurre debido a que la protección contra objetos serializados busca un 0: seguido por un entero, pero no considera 0:+ seguido por un entero.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-15 CVE Reserved
- 2019-01-15 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-11-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://build.prestashop.com/news/prestashop-1-7-2-5-maintenance-release | Release Notes |
URL | Date | SRC |
---|---|---|
https://blog.ripstech.com/2018/prestashop-remote-code-execution | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Prestashop Search vendor "Prestashop" | Prestashop Search vendor "Prestashop" for product "Prestashop" | < 1.7.2.5 Search vendor "Prestashop" for product "Prestashop" and version " < 1.7.2.5" | - |
Affected
|