CVE-2018-19124: Path Traversal
Published Nov 9, 2018
·Updated
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 on Windows allows remote attackers to write to arbitrary image files.
Affected Software
3 affected components
Prestashop PrestaShop>=1.6.0.1<1.6.1.23
Prestashop PrestaShop>=1.7.0.0<1.7.4.4
Microsoft Windows
Remediation
Patch Available
Patch Available
Event History
Nov 9, 2018
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19124?
The severity of CVE-2018-19124 is classified as high due to its potential to allow remote attackers to write arbitrary files.
2
What versions of PrestaShop are affected by CVE-2018-19124?
CVE-2018-19124 affects PrestaShop versions 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 on Windows.
3
How do I fix CVE-2018-19124?
To fix CVE-2018-19124, upgrade PrestaShop to version 1.6.1.23 or 1.7.4.4 or later.
4
Can CVE-2018-19124 be exploited remotely?
Yes, CVE-2018-19124 can be exploited remotely, allowing attackers to write to arbitrary image files.
5
What are the implications of CVE-2018-19124 for a PrestaShop site?
The implications of CVE-2018-19124 include potential unauthorized file uploads and modifications, which can lead to further attacks on the site.