CVE-2024-33836
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In the module "JA Marketplace" (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop, a guest can upload files with extensions .php. In version 6.X, the method `JmarketplaceproductModuleFrontController::init()` and in version 8.X, the method `JmarketplaceSellerproductModuleFrontController::init()` allow upload of .php files, which will lead to a critical vulnerability.
En el módulo "JA Marketplace" (jamarketplace) hasta la versión 9.0.1 del Módulo JA para PrestaShop, un invitado puede cargar archivos con extensiones .php. En la versión 6.X, el método `JmarketplaceproductModuleFrontController::init()` y en la versión 8.X, el método `JmarketplaceSellerproductModuleFrontController::init()` permiten cargar archivos .php, lo que conducirá a una vulnerabilidad crítica.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-04-26 CVE Reserved
- 2024-06-19 CVE Published
- 2024-06-20 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/friends-of-presta/security-advisories/blob/main/_posts/2024-06-18-jamarketplace.md |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Prestashopmodules Search vendor "Prestashopmodules" | Jamarketplace Search vendor "Prestashopmodules" for product "Jamarketplace" | * | - |
Affected
|