Record summary

CVE-2018-10942 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 28, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALPrestashop AttributeWizardPro Module - Arbitrary File UploadCVSS 9.8

In the Attribute Wizard addon 1.6.9 for PrestaShop allows remote attackers to execute arbitrary code by uploading a php file.

Impact

Unauthenticated attackers can upload and execute arbitrary PHP files, leading to complete server compromise, data theft, and potential lateral movement within the network.

Remediation

Remove or update the Attribute Wizard addon to a patched version.

WeaknessesCWE-434
AuthorsMaStErChO
Template tagsprestashopattributewizardprointrusivefile-uploadcve2018cveattribute_wizard_projectvkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:attribute_wizard_project:attribute_wizard:1.6.9:*:*:*:*:prestashop:*:*

Source: ProjectDiscovery

References

2