CVE-2018-10942
attribute_wizard_project attribute_wizard Unrestricted Upload of File with Dangerous Type
Record summary
CVE-2018-10942 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 28, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
attribute_wizardBrowse attribute_wizard_project / attribute_wizard | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALPrestashop AttributeWizardPro Module - Arbitrary File UploadCVSS 9.8
In the Attribute Wizard addon 1.6.9 for PrestaShop allows remote attackers to execute arbitrary code by uploading a php file.
Impact
Unauthenticated attackers can upload and execute arbitrary PHP files, leading to complete server compromise, data theft, and potential lateral movement within the network.
Remediation
Remove or update the Attribute Wizard addon to a patched version.
Source: ProjectDiscovery