CVE-2018-10942: Malicious File Upload
Published May 10, 2018
·Updated
modules/attributewizardpro/fileupload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file.
Affected Software
2 affected components
Attribute Wizard Project Attribute Wizard Prestashop=1.6.9
Prestashop PrestaShop>=1.4.0.1<=1.6.1.18
Event History
May 10, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10942?
CVE-2018-10942 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2018-10942?
To fix CVE-2018-10942, upgrade the Attribute Wizard addon to version 1.6.10 or later.
3
Who is affected by CVE-2018-10942?
CVE-2018-10942 affects users of the Attribute Wizard addon version 1.6.9 on PrestaShop versions 1.4.0.1 through 1.6.1.18.
4
What type of vulnerability is CVE-2018-10942?
CVE-2018-10942 is an arbitrary code execution vulnerability caused by insecure file uploads.
5
Can CVE-2018-10942 be exploited without authentication?
Yes, CVE-2018-10942 can be exploited by remote attackers without authentication.