CVE-2018-19355
modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a php file via modules/orderfiles/upload.php with auptype equal to product (for upload destinations under modules/productfiles), order (for upload destinations under modules/files), or cart (for upload destinations under modules/cartfiles).
- Affected products
- Prestashop
- Prestashop
- ≤ 1.7.0.0
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 3.5% (88th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2018-11-19
CVE-2018-19355 at NVD
1 known exploit for CVE-2018-19355
Proof-of-concept code and exploit modules indexed by Sploitus