CVE-2018-19126: Malicious File Upload
Published Nov 9, 2018
·Updated
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload.
Affected Software
2 affected components
Prestashop PrestaShop>=1.6.0.1<1.6.1.23
Prestashop PrestaShop>=1.7.0.0<1.7.4.4
Remediation
Patch Available
Patch Available
Event History
Nov 9, 2018
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19126?
CVE-2018-19126 has a critical severity rating as it allows remote code execution via file uploads.
2
How do I fix CVE-2018-19126?
To fix CVE-2018-19126, upgrade PrestaShop to version 1.6.1.23 or 1.7.4.4 or later.
3
What versions of PrestaShop are affected by CVE-2018-19126?
CVE-2018-19126 affects PrestaShop versions prior to 1.6.1.23 and 1.7.4.4.
4
How can attackers exploit CVE-2018-19126?
Attackers can exploit CVE-2018-19126 by uploading malicious files to execute arbitrary code on the server.
5
Is CVE-2018-19126 a common vulnerability in PrestaShop?
Yes, CVE-2018-19126 is recognized as a significant vulnerability impacting various installations of PrestaShop.