CVE-2018-8823
PrestaShop Responsive Mega Menu Module - Remote Code Execution
Record summary
CVE-2018-8823 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute arbitrary PHP code via the code parameter.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALPrestaShop Responsive Mega Menu Module - Remote Code ExecutionCVSS 9.8
The 'Responsive Mega Menu' module for PrestaShop is prone to a remote code execution and SQL injection vulnerability. modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop allows remote attackers to execute an SQL injection or remote code execution through function calls in the code parameter.
Impact
Unauthenticated attackers can execute arbitrary PHP code or SQL commands through the module, leading to complete PrestaShop compromise and access to customer data.
Remediation
Remove the vulnerable Responsive Mega Menu Pro module or upgrade to a patched version.
Source: ProjectDiscovery