CVE-2018-19126
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload.
- Affected products
- Prestashop
- Prestashop
- < 1.6.1.23, 1.7.4.4
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 22.5% (98th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2018-11-09
CVE-2018-19126 at NVD
5 known exploits for CVE-2018-19126
Proof-of-concept code and exploit modules indexed by Sploitus